
{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "text": "Copyright \u00a9 Oracle. All rights reserved.",
            "tlp": {
                "label": "WHITE",
                "url": "https://www.first.org/tlp"
            }
        },
        "lang": "en",
        "publisher": {
            "category": "vendor",
            "name": "Oracle",
            "namespace": "https://www.oracle.com"
        },
        "references": [
            {
                "summary": "URL to html version of Advisory",
                "url": "https://www.oracle.com/security-alerts/cpujul2026.html"
            },
            {
                "category": "self",
                "summary": "URL to CSAF version of Advisory",
                "url": "https://www.oracle.com/docs/tech/security-alerts/cpujul2026csaf.json"
            }
        ],
        "title": "Oracle Critical Patch Update Advisory - July 2026 - Oracle CSAF",
        "tracking": {
            "current_release_date": "2026-07-21T13:00:00-07:00",
            "id": "CPUJul2026csaf",
            "initial_release_date": "2026-07-21T13:00:00-07:00",
            "revision_history": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "number": "1",
                    "summary": "Initial Release"
                }
            ],
            "status": "final",
            "version": "1"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle APEX Version 24.1",
                                        "product": {
                                            "name": "Oracle APEX Version 24.1",
                                            "product_id": "P-1348V-24.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:apex:24.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle APEX Version 24.2",
                                        "product": {
                                            "name": "Oracle APEX Version 24.2",
                                            "product_id": "P-1348V-24.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:apex:24.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle APEX Version 26.1",
                                        "product": {
                                            "name": "Oracle APEX Version 26.1",
                                            "product_id": "P-1348V-26.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:apex:26.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle APEX"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle APEX"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle BI Publisher Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle BI Publisher Version 12.2.1.4.0",
                                            "product_id": "P-1479V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle BI Publisher Version 26.01.0.0.0",
                                        "product": {
                                            "name": "Oracle BI Publisher Version 26.01.0.0.0",
                                            "product_id": "P-1479V-26.01.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle BI Publisher Version 8.2.0.0.0",
                                        "product": {
                                            "name": "Oracle BI Publisher Version 8.2.0.0.0",
                                            "product_id": "P-1479V-8.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle BI Publisher"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Business Intelligence Enterprise Edition Version 26.01.0.0.0",
                                        "product": {
                                            "name": "Oracle Business Intelligence Enterprise Edition Version 26.01.0.0.0",
                                            "product_id": "P-2025V-26.01.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                                            "product_id": "P-2025V-8.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Business Intelligence Enterprise Edition"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Analytics"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Application Testing Suite Version 13.3.0.1",
                                        "product": {
                                            "name": "Oracle Application Testing Suite Version 13.3.0.1",
                                            "product_id": "P-4622V-13.3.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Application Testing Suite"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Application Testing Suite"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 25.1",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 25.1",
                                            "product_id": "P-14634V-25.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:25.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.0.0",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.0.0",
                                            "product_id": "P-14634V-26.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.1.0",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.1.0",
                                            "product_id": "P-14634V-26.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.2.0",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.2.0",
                                            "product_id": "P-14634V-26.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.3.0",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.3.0",
                                            "product_id": "P-14634V-26.3.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.3.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.5.0",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.5.0",
                                            "product_id": "P-14634V-26.5.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.5.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Autonomous Health Framework"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Autonomous Health Framework"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search(Oracle Commerce Guided Search_Content Acquisition System) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search(Oracle Commerce Guided Search_Content Acquisition System) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search(Oracle Commerce Guided Search_Experience Manager) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search(Oracle Commerce Guided Search_Experience Manager) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search_Experience Manager)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Commerce Guided Search"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search_\\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search_\\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search_\\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search_\\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search Platform Services(Oracle Commerce Guided Search Platform Services_Forge) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search Platform Services(Oracle Commerce Guided Search Platform Services_Forge) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search_platform_services:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Commerce Guided Search Platform Services"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Platform Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Platform Version 11.4.0",
                                            "product_id": "P-9348V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Commerce Platform"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Service Center Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Service Center Version 11.4.0",
                                            "product_id": "P-9351V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_service_center:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Commerce Service Center"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Commerce"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Management Cloud Engine Version 25.2.0.0.0",
                                        "product": {
                                            "name": "Management Cloud Engine Version 25.2.0.0.0",
                                            "product_id": "P-14252V-25.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:management_cloud_engine:25.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Management Cloud Engine"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Cloud Native Session Border Controller Version 26.0.0",
                                        "product": {
                                            "name": "Oracle Cloud Native Session Border Controller Version 26.0.0",
                                            "product_id": "P-14762V-26.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:cloud_native_session_border_controller:26.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Cloud Native Session Border Controller"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0.0",
                                            "product_id": "P-9742V-15.0.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0.0-15.0.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0.0-15.0.1.0.0",
                                            "product_id": "P-9742V-15.0.0.0.0-15.0.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.0.0.0-15.0.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.1.0.0",
                                            "product_id": "P-9742V-15.0.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.1.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.1.0.0.0",
                                            "product_id": "P-9742V-15.1.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.1.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.1.0.0.0-15.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.1.0.0.0-15.2.0.0.0",
                                            "product_id": "P-9742V-15.1.0.0.0-15.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.1.0.0.0-15.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.2.0.0.0",
                                            "product_id": "P-9742V-15.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications BRM - Elastic Charging Engine"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_BRM Server) Version 15.0.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_BRM Server) Version 15.0.0.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.0.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.0.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.0.0.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.0.0.0.0-15.0.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.0.0.0.0-15.0.1.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0-15.0.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0.0-15.0.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_BRM Server) Version 15.0.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_BRM Server) Version 15.0.1.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.0.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.0.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.0.1.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_BRM Server) Version 15.1.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_BRM Server) Version 15.1.0.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.1.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.1.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.1.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.1.0.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.1.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.1.0.0.0-15.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.1.0.0.0-15.2.0.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0-15.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.1.0.0.0-15.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_BRM Server) Version 15.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_BRM Server) Version 15.2.0.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Billing and Revenue Management(Oracle Communications Billing and Revenue Management_Platform) Version 15.2.0.0.0",
                                            "product_id": "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Billing and Revenue Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Binding Support Function Version 25.1.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Binding Support Function Version 25.1.200",
                                            "product_id": "P-14121V-25.1.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:25.1.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Binding Support Function Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Binding Support Function Version 25.2.200",
                                            "product_id": "P-14121V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Binding Support Function"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Certificate Management Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Certificate Management Version 25.2.200",
                                            "product_id": "P-14868V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_certificate_management:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Certificate Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Console Version 25.1.203",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Console Version 25.1.203",
                                            "product_id": "P-14250V-25.1.203",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_console:25.1.203:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Console Version 25.2.201",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Console Version 25.2.201",
                                            "product_id": "P-14250V-25.2.201",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_console:25.2.201:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Console"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core DBTier Version 25.1.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core DBTier Version 25.1.200",
                                            "product_id": "P-14974V-25.1.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_dbtier:25.1.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core DBTier Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core DBTier Version 25.2.200",
                                            "product_id": "P-14974V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_dbtier:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core DBTier"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Network Exposure Function Version 24.2.0",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Network Exposure Function Version 24.2.0",
                                            "product_id": "P-14122V-24.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:24.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Network Exposure Function Version 24.2.5",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Network Exposure Function Version 24.2.5",
                                            "product_id": "P-14122V-24.2.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:24.2.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Network Exposure Function"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 25.2.200",
                                            "product_id": "P-14125V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Network Repository Function(Oracle Communications Cloud Native Core Network Repository Function_CONFIG) Version 25.2.201",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Network Repository Function(Oracle Communications Cloud Native Core Network Repository Function_CONFIG) Version 25.2.201",
                                            "product_id": "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:25.2.201:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Network Repository Function(Oracle Communications Cloud Native Core Network Repository Function_Configuration) Version 25.2.201",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Network Repository Function(Oracle Communications Cloud Native Core Network Repository Function_Configuration) Version 25.2.201",
                                            "product_id": "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:25.2.201:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Network Repository Function(Oracle Communications Cloud Native Core Network Repository Function_NRF) Version 25.2.201",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Network Repository Function(Oracle Communications Cloud Native Core Network Repository Function_NRF) Version 25.2.201",
                                            "product_id": "P-14118(Oracle Communications Cloud Native Core Network Repository Function_NRF)V-25.2.201",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:25.2.201:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Network Repository Function"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 25.2.200",
                                            "product_id": "P-14130V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Network Slice Selection Function"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Policy Version 24.2.0",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Policy Version 24.2.0",
                                            "product_id": "P-14277V-24.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:24.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Policy Version 24.2.7",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Policy Version 24.2.7",
                                            "product_id": "P-14277V-24.2.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:24.2.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Policy Version 25.1.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Policy Version 25.1.200",
                                            "product_id": "P-14277V-25.1.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:25.1.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Policy Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Policy Version 25.2.200",
                                            "product_id": "P-14277V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Policy"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework) Version 25.1.203",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework) Version 25.1.203",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.1.203",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.1.203:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration) Version 25.1.203",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration) Version 25.1.203",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.1.203:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP) Version 25.1.203",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP) Version 25.1.203",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.1.203:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info) Version 25.1.203",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info) Version 25.1.203",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.1.203:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework) Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework) Version 25.2.200",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration) Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration) Version 25.2.200",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP) Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP) Version 25.2.200",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info) Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info) Version 25.2.200",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.1.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.1.200",
                                            "product_id": "P-14117V-25.1.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:25.1.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.2.100",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.2.100",
                                            "product_id": "P-14117V-25.2.100",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:25.2.100:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.2.200",
                                            "product_id": "P-14117V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Service Communication Proxy"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Unified Data Repository(Oracle Communications Cloud Native Core Unified Data Repository_Install) Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Unified Data Repository(Oracle Communications Cloud Native Core Unified Data Repository_Install) Version 25.2.200",
                                            "product_id": "P-14119(Oracle Communications Cloud Native Core Unified Data Repository_Install)V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 25.2.200",
                                            "product_id": "P-14119V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Unified Data Repository(Oracle Communications Cloud Native Core Unified Data Repository_Install) Version 25.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Unified Data Repository(Oracle Communications Cloud Native Core Unified Data Repository_Install) Version 25.200",
                                            "product_id": "P-14119(Oracle Communications Cloud Native Core Unified Data Repository_Install)V-25.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:25.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Unified Data Repository"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Converged Application Server Version 8.2",
                                        "product": {
                                            "name": "Oracle Communications Converged Application Server Version 8.2",
                                            "product_id": "P-5382V-8.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_converged_application_server:8.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Converged Application Server Version 8.3",
                                        "product": {
                                            "name": "Oracle Communications Converged Application Server Version 8.3",
                                            "product_id": "P-5382V-8.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_converged_application_server:8.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Converged Application Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Convergent Charging Controller Version 15.0.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Convergent Charging Controller Version 15.0.0.0.0",
                                            "product_id": "P-12985V-15.0.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:15.0.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Convergent Charging Controller Version 15.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Convergent Charging Controller Version 15.2.0.0.0",
                                            "product_id": "P-12985V-15.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:15.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Convergent Charging Controller"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 6.0.2.2.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 6.0.2.2.0",
                                            "product_id": "P-10899V-6.0.2.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:6.0.2.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 6.1.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 6.1.0.0.0",
                                            "product_id": "P-10899V-6.1.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:6.1.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 6.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 6.2.0.0.0",
                                            "product_id": "P-10899V-6.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:6.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 6.3.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 6.3.0.0.0",
                                            "product_id": "P-10899V-6.3.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:6.3.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.0.0",
                                            "product_id": "P-10899V-9.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.0.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.0.0.0.0",
                                            "product_id": "P-10899V-9.0.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.0.0.0.0-9.3.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.0.0.0.0-9.3.0.0.0",
                                            "product_id": "P-10899V-9.0.0.0.0-9.3.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.0.0.0-9.3.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.0.1",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.0.1",
                                            "product_id": "P-10899V-9.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.0.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.0.1.0.0",
                                            "product_id": "P-10899V-9.0.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.1.0-10.0.15",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.1.0-10.0.15",
                                            "product_id": "P-10899V-9.1.0-10.0.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.1.0-10.0.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.1.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.1.0.0.0",
                                            "product_id": "P-10899V-9.1.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.1.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.2.0.0.0",
                                            "product_id": "P-10899V-9.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Diameter Signaling Router Version 9.3.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Diameter Signaling Router Version 9.3.0.0.0",
                                            "product_id": "P-10899V-9.3.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.3.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Diameter Signaling Router"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Instant Messaging Server Version 10.0.1.8.0",
                                        "product": {
                                            "name": "Oracle Communications Instant Messaging Server Version 10.0.1.8.0",
                                            "product_id": "P-8495V-10.0.1.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Instant Messaging Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Messaging Server Version 8.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications Messaging Server Version 8.1.0.0",
                                            "product_id": "P-8496V-8.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_messaging_server:8.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Messaging Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Analytics Data Director Version 24.2.0",
                                        "product": {
                                            "name": "Oracle Communications Network Analytics Data Director Version 24.2.0",
                                            "product_id": "P-14547V-24.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Analytics Data Director Version 24.2.0.0.1",
                                        "product": {
                                            "name": "Oracle Communications Network Analytics Data Director Version 24.2.0.0.1",
                                            "product_id": "P-14547V-24.2.0.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.2.0.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Analytics Data Director Version 24.3.4",
                                        "product": {
                                            "name": "Oracle Communications Network Analytics Data Director Version 24.3.4",
                                            "product_id": "P-14547V-24.3.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.3.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Analytics Data Director Version 25.1.200",
                                        "product": {
                                            "name": "Oracle Communications Network Analytics Data Director Version 25.1.200",
                                            "product_id": "P-14547V-25.1.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.1.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Analytics Data Director Version 25.2.100",
                                        "product": {
                                            "name": "Oracle Communications Network Analytics Data Director Version 25.2.100",
                                            "product_id": "P-14547V-25.2.100",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.2.100:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Analytics Data Director Version 25.2.200",
                                        "product": {
                                            "name": "Oracle Communications Network Analytics Data Director Version 25.2.200",
                                            "product_id": "P-14547V-25.2.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.2.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Network Analytics Data Director"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Charging and Control Version 15.0.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Network Charging and Control Version 15.0.0.0.0",
                                            "product_id": "P-4623V-15.0.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:15.0.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Charging and Control Version 15.0.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications Network Charging and Control Version 15.0.1.0.0",
                                            "product_id": "P-4623V-15.0.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:15.0.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Network Charging and Control"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Integrity Version 7.3.6",
                                        "product": {
                                            "name": "Oracle Communications Network Integrity Version 7.3.6",
                                            "product_id": "P-4491V-7.3.6",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Integrity Version 7.4.0",
                                        "product": {
                                            "name": "Oracle Communications Network Integrity Version 7.4.0",
                                            "product_id": "P-4491V-7.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Integrity Version 7.5.0",
                                        "product": {
                                            "name": "Oracle Communications Network Integrity Version 7.5.0",
                                            "product_id": "P-4491V-7.5.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.5.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Network Integrity Version 8.0.0",
                                        "product": {
                                            "name": "Oracle Communications Network Integrity Version 8.0.0",
                                            "product_id": "P-4491V-8.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_network_integrity:8.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Network Integrity"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0.0-15.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0.0-15.2.0.0.0",
                                            "product_id": "P-2269V-15.0.0.0.0-15.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.0.0.0-15.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Offline Mediation Controller"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Operations Monitor Version 5.2",
                                        "product": {
                                            "name": "Oracle Communications Operations Monitor Version 5.2",
                                            "product_id": "P-10761V-5.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:5.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Operations Monitor Version 6.0",
                                        "product": {
                                            "name": "Oracle Communications Operations Monitor Version 6.0",
                                            "product_id": "P-10761V-6.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:6.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Operations Monitor Version 6.1",
                                        "product": {
                                            "name": "Oracle Communications Operations Monitor Version 6.1",
                                            "product_id": "P-10761V-6.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:6.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Operations Monitor"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Order and Service Management Version 7.4.1",
                                        "product": {
                                            "name": "Oracle Communications Order and Service Management Version 7.4.1",
                                            "product_id": "P-2270V-7.4.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.4.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Order and Service Management Version 7.5.0",
                                        "product": {
                                            "name": "Oracle Communications Order and Service Management Version 7.5.0",
                                            "product_id": "P-2270V-7.5.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.5.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Order and Service Management Version 8.0.0",
                                        "product": {
                                            "name": "Oracle Communications Order and Service Management Version 8.0.0",
                                            "product_id": "P-2270V-8.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:8.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Order and Service Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Performance Intelligence Center Version 10.5.0.1.0",
                                        "product": {
                                            "name": "Oracle Communications Performance Intelligence Center Version 10.5.0.1.0",
                                            "product_id": "P-11044V-10.5.0.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_performance_intelligence_center:10.5.0.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Performance Intelligence Center Version 10.5.0.2.0",
                                        "product": {
                                            "name": "Oracle Communications Performance Intelligence Center Version 10.5.0.2.0",
                                            "product_id": "P-11044V-10.5.0.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_performance_intelligence_center:10.5.0.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Performance Intelligence Center"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Policy Management Version 15.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Policy Management Version 15.0.0.0",
                                            "product_id": "P-10900V-15.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_policy_management:15.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Policy Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Pricing Design Center Version 15.0.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Pricing Design Center Version 15.0.0.0.0",
                                            "product_id": "P-9437V-15.0.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.0.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Pricing Design Center Version 15.0.1.0.0",
                                        "product": {
                                            "name": "Oracle Communications Pricing Design Center Version 15.0.1.0.0",
                                            "product_id": "P-9437V-15.0.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.0.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Pricing Design Center Version 15.1.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Pricing Design Center Version 15.1.0.0.0",
                                            "product_id": "P-9437V-15.1.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.1.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Pricing Design Center Version 15.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Communications Pricing Design Center Version 15.2.0.0.0",
                                            "product_id": "P-9437V-15.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Pricing Design Center"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Service Catalog and Design Version 8.0.0.7.0",
                                        "product": {
                                            "name": "Oracle Communications Service Catalog and Design Version 8.0.0.7.0",
                                            "product_id": "P-2283V-8.0.0.7.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.0.0.7.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Service Catalog and Design Version 8.0.0.7.0-8.3.0.2.0",
                                        "product": {
                                            "name": "Oracle Communications Service Catalog and Design Version 8.0.0.7.0-8.3.0.2.0",
                                            "product_id": "P-2283V-8.0.0.7.0-8.3.0.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.0.0.7.0-8.3.0.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Service Catalog and Design Version 8.0.0.7.0-8.3.0.3.0",
                                        "product": {
                                            "name": "Oracle Communications Service Catalog and Design Version 8.0.0.7.0-8.3.0.3.0",
                                            "product_id": "P-2283V-8.0.0.7.0-8.3.0.3.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.0.0.7.0-8.3.0.3.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Service Catalog and Design Version 8.1.0.6.0",
                                        "product": {
                                            "name": "Oracle Communications Service Catalog and Design Version 8.1.0.6.0",
                                            "product_id": "P-2283V-8.1.0.6.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.1.0.6.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Service Catalog and Design"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Session Border Controller Version 10.0.0",
                                        "product": {
                                            "name": "Oracle Communications Session Border Controller Version 10.0.0",
                                            "product_id": "P-10750V-10.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:10.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Session Border Controller Version 10.1.0",
                                        "product": {
                                            "name": "Oracle Communications Session Border Controller Version 10.1.0",
                                            "product_id": "P-10750V-10.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:10.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Session Border Controller Version 9.3.0",
                                        "product": {
                                            "name": "Oracle Communications Session Border Controller Version 9.3.0",
                                            "product_id": "P-10750V-9.3.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.3.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Session Border Controller"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Unified Assurance(Oracle Communications Unified Assurance_Core) Version 6.1.1-7.0.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Assurance(Oracle Communications Unified Assurance_Core) Version 6.1.1-7.0.0",
                                            "product_id": "P-14597(Oracle Communications Unified Assurance_Core)V-6.1.1-7.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.1.1-7.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Communications Unified Assurance Version 6.1.1-7.0.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Assurance Version 6.1.1-7.0.0",
                                            "product_id": "P-14597V-6.1.1-7.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.1.1-7.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Unified Assurance Version 7.0.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Assurance Version 7.0.0",
                                            "product_id": "P-14597V-7.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:7.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Unified Assurance"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Unified Inventory Management Version 7.5.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Inventory Management Version 7.5.0",
                                            "product_id": "P-4516V-7.5.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Unified Inventory Management Version 7.5.1",
                                        "product": {
                                            "name": "Oracle Communications Unified Inventory Management Version 7.5.1",
                                            "product_id": "P-4516V-7.5.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Unified Inventory Management Version 7.6.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Inventory Management Version 7.6.0",
                                            "product_id": "P-4516V-7.6.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.6.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Unified Inventory Management Version 7.7.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Inventory Management Version 7.7.0",
                                            "product_id": "P-4516V-7.7.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.7.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Unified Inventory Management Version 7.8.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Inventory Management Version 7.8.0",
                                            "product_id": "P-4516V-7.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Unified Inventory Management Version 8.0.1",
                                        "product": {
                                            "name": "Oracle Communications Unified Inventory Management Version 8.0.1",
                                            "product_id": "P-4516V-8.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:8.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Unified Inventory Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications User Data Repository Version 15.0",
                                        "product": {
                                            "name": "Oracle Communications User Data Repository Version 15.0",
                                            "product_id": "P-11108V-15.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_user_data_repository:15.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications User Data Repository"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Communications Broker Version 4.2.0",
                                        "product": {
                                            "name": "Oracle Enterprise Communications Broker Version 4.2.0",
                                            "product_id": "P-10758V-4.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:4.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Communications Broker Version 5.0.0",
                                        "product": {
                                            "name": "Oracle Enterprise Communications Broker Version 5.0.0",
                                            "product_id": "P-10758V-5.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:5.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Communications Broker Version 5.1.0",
                                        "product": {
                                            "name": "Oracle Enterprise Communications Broker Version 5.1.0",
                                            "product_id": "P-10758V-5.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:5.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Communications Broker"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Communications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera Gateway Version 21.12-21.12.17",
                                        "product": {
                                            "name": "Primavera Gateway Version 21.12-21.12.17",
                                            "product_id": "P-10605V-21.12-21.12.17",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_gateway:21.12-21.12.17:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Primavera Gateway"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0.0-21.12.21.8",
                                        "product": {
                                            "name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0.0-21.12.21.8",
                                            "product_id": "P-5579V-21.12.0.0-21.12.21.8",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:21.12.0.0-21.12.21.8:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0.0-22.12.21.2",
                                        "product": {
                                            "name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0.0-22.12.21.2",
                                            "product_id": "P-5579V-22.12.0.0-22.12.21.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:22.12.0.0-22.12.21.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera P6 Enterprise Project Portfolio Management Version 23.12.0-23.12.19",
                                        "product": {
                                            "name": "Primavera P6 Enterprise Project Portfolio Management Version 23.12.0-23.12.19",
                                            "product_id": "P-5579V-23.12.0-23.12.19",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:23.12.0-23.12.19:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0-24.12.14",
                                        "product": {
                                            "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0-24.12.14",
                                            "product_id": "P-5579V-24.12.0-24.12.14",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:24.12.0-24.12.14:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera P6 Enterprise Project Portfolio Management Version 25.12.0-25.12.4",
                                        "product": {
                                            "name": "Primavera P6 Enterprise Project Portfolio Management Version 25.12.0-25.12.4",
                                            "product_id": "P-5579V-25.12.0-25.12.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:25.12.0-25.12.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Primavera P6 Enterprise Project Portfolio Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera Unifier Version 21.12.0-21.12.17",
                                        "product": {
                                            "name": "Primavera Unifier Version 21.12.0-21.12.17",
                                            "product_id": "P-10354V-21.12.0-21.12.17",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_unifier:21.12.0-21.12.17:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera Unifier Version 22.12.0-22.12.15",
                                        "product": {
                                            "name": "Primavera Unifier Version 22.12.0-22.12.15",
                                            "product_id": "P-10354V-22.12.0-22.12.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_unifier:22.12.0-22.12.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera Unifier Version 23.12.0-23.12.16",
                                        "product": {
                                            "name": "Primavera Unifier Version 23.12.0-23.12.16",
                                            "product_id": "P-10354V-23.12.0-23.12.16",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_unifier:23.12.0-23.12.16:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera Unifier Version 24.12.0-24.12.14",
                                        "product": {
                                            "name": "Primavera Unifier Version 24.12.0-24.12.14",
                                            "product_id": "P-10354V-24.12.0-24.12.14",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_unifier:24.12.0-24.12.14:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Primavera Unifier Version 25.12.0-25.12.6",
                                        "product": {
                                            "name": "Primavera Unifier Version 25.12.0-25.12.6",
                                            "product_id": "P-10354V-25.12.0-25.12.6",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:primavera_unifier:25.12.0-25.12.6:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Primavera Unifier"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Construction and Engineering"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Java VM) Version 19.3-19.30",
                                        "product": {
                                            "name": "Oracle Database Server(Java VM) Version 19.3-19.30",
                                            "product_id": "P-5(Java VM)V-19.3-19.30",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_java_vm:19.3-19.30:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Fleet Patching and Provisioning) Version 19.3-19.31",
                                        "product": {
                                            "name": "Oracle Database Server(Fleet Patching and Provisioning) Version 19.3-19.31",
                                            "product_id": "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_fleet_patching_and_provisioning:19.3-19.31:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(JDBC) Version 19.3-19.31",
                                        "product": {
                                            "name": "Oracle Database Server(JDBC) Version 19.3-19.31",
                                            "product_id": "P-5(JDBC)V-19.3-19.31",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_jdbc:19.3-19.31:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Java VM) Version 19.3-19.31",
                                        "product": {
                                            "name": "Oracle Database Server(Java VM) Version 19.3-19.31",
                                            "product_id": "P-5(Java VM)V-19.3-19.31",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_java_vm:19.3-19.31:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(RDBMS) Version 19.3-19.31",
                                        "product": {
                                            "name": "Oracle Database Server(RDBMS) Version 19.3-19.31",
                                            "product_id": "P-5(RDBMS)V-19.3-19.31",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_rdbms:19.3-19.31:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Oracle Spatial and Graph) Version 19.3-19.31",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Spatial and Graph) Version 19.3-19.31",
                                            "product_id": "P-619(Oracle Spatial and Graph)V-19.3-19.31",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_spatial_and_graph:19.3-19.31:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Fleet Patching and Provisioning) Version 21.3-21.22",
                                        "product": {
                                            "name": "Oracle Database Server(Fleet Patching and Provisioning) Version 21.3-21.22",
                                            "product_id": "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_fleet_patching_and_provisioning:21.3-21.22:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 21.3-21.22",
                                        "product": {
                                            "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 21.3-21.22",
                                            "product_id": "P-5(GraalVM Multilingual Engine)V-21.3-21.22",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:21.3-21.22:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(JDBC) Version 21.3-21.22",
                                        "product": {
                                            "name": "Oracle Database Server(JDBC) Version 21.3-21.22",
                                            "product_id": "P-5(JDBC)V-21.3-21.22",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_jdbc:21.3-21.22:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Java VM) Version 21.3-21.22",
                                        "product": {
                                            "name": "Oracle Database Server(Java VM) Version 21.3-21.22",
                                            "product_id": "P-5(Java VM)V-21.3-21.22",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_java_vm:21.3-21.22:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(RDBMS) Version 21.3-21.22",
                                        "product": {
                                            "name": "Oracle Database Server(RDBMS) Version 21.3-21.22",
                                            "product_id": "P-5(RDBMS)V-21.3-21.22",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_rdbms:21.3-21.22:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Oracle Spatial and Graph) Version 21.3-21.22",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Spatial and Graph) Version 21.3-21.22",
                                            "product_id": "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_spatial_and_graph:21.3-21.22:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Java VM) Version 23.4.0-23.26.1",
                                        "product": {
                                            "name": "Oracle Database Server(Java VM) Version 23.4.0-23.26.1",
                                            "product_id": "P-5(Java VM)V-23.4.0-23.26.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_java_vm:23.4.0-23.26.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Database) Version 23.4.0-23.26.2",
                                        "product": {
                                            "name": "Oracle Database Server(Database) Version 23.4.0-23.26.2",
                                            "product_id": "P-5(Database)V-23.4.0-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_database:23.4.0-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Fleet Patching and Provisioning) Version 23.4.0-23.26.2",
                                        "product": {
                                            "name": "Oracle Database Server(Fleet Patching and Provisioning) Version 23.4.0-23.26.2",
                                            "product_id": "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_fleet_patching_and_provisioning:23.4.0-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 23.4.0-23.26.2",
                                        "product": {
                                            "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 23.4.0-23.26.2",
                                            "product_id": "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:23.4.0-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(JDBC) Version 23.4.0-23.26.2",
                                        "product": {
                                            "name": "Oracle Database Server(JDBC) Version 23.4.0-23.26.2",
                                            "product_id": "P-5(JDBC)V-23.4.0-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_jdbc:23.4.0-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Java VM) Version 23.4.0-23.26.2",
                                        "product": {
                                            "name": "Oracle Database Server(Java VM) Version 23.4.0-23.26.2",
                                            "product_id": "P-5(Java VM)V-23.4.0-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_java_vm:23.4.0-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(RDBMS) Version 23.4.0-23.26.2",
                                        "product": {
                                            "name": "Oracle Database Server(RDBMS) Version 23.4.0-23.26.2",
                                            "product_id": "P-5(RDBMS)V-23.4.0-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_rdbms:23.4.0-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Database Server(Oracle Spatial and Graph) Version 23.4.0-23.26.2",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Spatial and Graph) Version 23.4.0-23.26.2",
                                            "product_id": "P-619(Oracle Spatial and Graph)V-23.4.0-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_spatial_and_graph:23.4.0-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Database Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Net Services Version 19.3-19.31",
                                        "product": {
                                            "name": "Oracle Net Services Version 19.3-19.31",
                                            "product_id": "P-115V-19.3-19.31",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:net_services:19.3-19.31:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Net Services Version 21.3-21.22",
                                        "product": {
                                            "name": "Oracle Net Services Version 21.3-21.22",
                                            "product_id": "P-115V-21.3-21.22",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:net_services:21.3-21.22:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Net Services Version 23.4.0-23.26.2",
                                        "product": {
                                            "name": "Oracle Net Services Version 23.4.0-23.26.2",
                                            "product_id": "P-115V-23.4.0-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:net_services:23.4.0-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Net Services"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Database Server"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "HRMS (Australia) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "HRMS (Australia) Version 12.2.3-12.2.15",
                                            "product_id": "P-422V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "HRMS (Australia)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Advanced Benefits Version 12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Benefits Version 12.2.15",
                                            "product_id": "P-290V-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_benefits:12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Benefits Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Benefits Version 12.2.3-12.2.15",
                                            "product_id": "P-290V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_benefits:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Benefits Version 12.2.4-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Benefits Version 12.2.4-12.2.15",
                                            "product_id": "P-290V-12.2.4-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_benefits:12.2.4-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Benefits Version 12.2.7-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Benefits Version 12.2.7-12.2.15",
                                            "product_id": "P-290V-12.2.7-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_benefits:12.2.7-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Advanced Benefits"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Collections Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Collections Version 12.2.3-12.2.15",
                                            "product_id": "P-782V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_collections:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Advanced Collections"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Inbound Telephony Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Inbound Telephony Version 12.2.3-12.2.15",
                                            "product_id": "P-265V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_inbound_telephony:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Advanced Inbound Telephony"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Outbound Telephony Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Outbound Telephony Version 12.2.3-12.2.15",
                                            "product_id": "P-785V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_outbound_telephony:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Advanced Outbound Telephony"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Planning Command Center Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Planning Command Center Version 12.2.3-12.2.15",
                                            "product_id": "P-4573V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_planning_command_center:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Advanced Planning Command Center"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Pricing Version 12.2.14-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Pricing Version 12.2.14-12.2.15",
                                            "product_id": "P-495V-12.2.14-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_pricing:12.2.14-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Pricing Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Pricing Version 12.2.3-12.2.15",
                                            "product_id": "P-495V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_pricing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Advanced Pricing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Advanced Supply Chain Planning Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Supply Chain Planning Version 12.2.3-12.2.15",
                                            "product_id": "P-719V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_supply_chain_planning:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Advanced Supply Chain Planning"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Application Object Library Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Application Object Library Version 12.2.3-12.2.15",
                                            "product_id": "P-510V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:application_object_library:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Application Object Library"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Applications DBA Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications DBA Version 12.2.3-12.2.15",
                                            "product_id": "P-166V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_dba:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Applications DBA"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Applications Framework Version 12.2.11-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications Framework Version 12.2.11-12.2.15",
                                            "product_id": "P-1472V-12.2.11-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_framework:12.2.11-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Applications Framework Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications Framework Version 12.2.3-12.2.15",
                                            "product_id": "P-1472V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_framework:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Applications Framework Version 12.2.8-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications Framework Version 12.2.8-12.2.15",
                                            "product_id": "P-1472V-12.2.8-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_framework:12.2.8-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Applications Framework"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Applications Manager Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications Manager Version 12.2.3-12.2.15",
                                            "product_id": "P-99V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_manager:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Applications Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Applications Technology Stack Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications Technology Stack Version 12.2.3-12.2.15",
                                            "product_id": "P-1745V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_technology_stack:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Applications Technology Stack"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Assets Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Assets Version 12.2.3-12.2.15",
                                            "product_id": "P-503V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:assets:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Assets"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Bills of Material Version 12.2.13-12.2.15",
                                        "product": {
                                            "name": "Oracle Bills of Material Version 12.2.13-12.2.15",
                                            "product_id": "P-571V-12.2.13-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bills_of_material:12.2.13-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Bills of Material Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Bills of Material Version 12.2.3-12.2.15",
                                            "product_id": "P-571V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bills_of_material:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Bills of Material"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Call Center Technology Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Call Center Technology Version 12.2.3-12.2.15",
                                            "product_id": "P-781V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:call_center_technology:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Call Center Technology"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Capacity Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Capacity Version 12.2.3-12.2.15",
                                            "product_id": "P-533V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:capacity:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Capacity"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Cash Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Cash Management Version 12.2.3-12.2.15",
                                            "product_id": "P-968V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:cash_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Cash Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Citizen Interaction Center Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Citizen Interaction Center Version 12.2.3-12.2.15",
                                            "product_id": "P-1185V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:citizen_interaction_center:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Citizen Interaction Center"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Common Application Components Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Common Application Components Version 12.2.3-12.2.15",
                                            "product_id": "P-83V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:common_application_components:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Common Application Components"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Common Applications Calendar Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Common Applications Calendar Version 12.2.3-12.2.15",
                                            "product_id": "P-1528V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:common_applications_calendar:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Common Applications Calendar"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Compensation Workbench Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Compensation Workbench Version 12.2.3-12.2.15",
                                            "product_id": "P-4427V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:compensation_workbench:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Compensation Workbench"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Complex Maintenance, Repair and Overhaul Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Complex Maintenance, Repair and Overhaul Version 12.2.3-12.2.15",
                                            "product_id": "P-1184V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:complex_maintenance__repair_and_overhaul:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Complex Maintenance, Repair and Overhaul"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Concurrent Processing Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Concurrent Processing Version 12.2.3-12.2.15",
                                            "product_id": "P-9303V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:concurrent_processing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Concurrent Processing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Configure to Order Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Configure to Order Version 12.2.3-12.2.15",
                                            "product_id": "P-776V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:configure_to_order:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Configure to Order"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Content Manager Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Content Manager Version 12.2.3-12.2.15",
                                            "product_id": "P-1145V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:content_manager:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Content Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Contracts Integration Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Contracts Integration Version 12.2.3-12.2.15",
                                            "product_id": "P-499V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:contracts_integration:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Contracts Integration"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Cost Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Cost Management Version 12.2.3-12.2.15",
                                            "product_id": "P-569V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:cost_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Cost Management Version V16",
                                        "product": {
                                            "name": "Oracle Cost Management Version V16",
                                            "product_id": "P-569V-V16",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:cost_management:v16:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Cost Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Customer Care Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Customer Care Version 12.2.3-12.2.15",
                                            "product_id": "P-105V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:customer_care:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Customer Care"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Customer Interaction History Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Customer Interaction History Version 12.2.3-12.2.15",
                                            "product_id": "P-1374V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:customer_interaction_history:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Customer Interaction History"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Customer Support Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Customer Support Version 12.2.3-12.2.15",
                                            "product_id": "P-1779V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:customer_support:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Customer Support"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Customers Online Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Customers Online Version 12.2.3-12.2.15",
                                            "product_id": "P-1284V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:customers_online:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Customers Online"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Demand Signal Repository Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Demand Signal Repository Version 12.2.3-12.2.15",
                                            "product_id": "P-4546V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:demand_signal_repository:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Demand Signal Repository"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Document Management and Collaboration Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Document Management and Collaboration Version 12.2.3-12.2.15",
                                            "product_id": "P-1314V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:document_management_and_collaboration:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Document Management and Collaboration"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle E-Business Intelligence Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle E-Business Intelligence Version 12.2.3-12.2.15",
                                            "product_id": "P-163V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:e-business_intelligence:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle E-Business Intelligence"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle E-Business Suite Integrated SOA Gateway Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle E-Business Suite Integrated SOA Gateway Version 12.2.3-12.2.15",
                                            "product_id": "P-4569V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:e-business_suite_integrated_soa_gateway:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle E-Business Suite Integrated SOA Gateway"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle E-Business Suite Secure Enterprise Search Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle E-Business Suite Secure Enterprise Search Version 12.2.3-12.2.15",
                                            "product_id": "P-4574V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:e-business_suite_secure_enterprise_search:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle E-Business Suite Secure Enterprise Search"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle E-Business Tax Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle E-Business Tax Version 12.2.3-12.2.15",
                                            "product_id": "P-1087V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:e-business_tax:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle E-Business Tax"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle EDI Gateway Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle EDI Gateway Version 12.2.3-12.2.15",
                                            "product_id": "P-509V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:edi_gateway:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle EDI Gateway"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Enterprise Asset Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Enterprise Asset Management Version 12.2.3-12.2.15",
                                            "product_id": "P-1142V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_asset_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Asset Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Command Center Framework Version V16",
                                        "product": {
                                            "name": "Oracle Enterprise Command Center Framework Version V16",
                                            "product_id": "P-13788V-V16",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_command_center_framework:v16:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Command Center Framework"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Field Service Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Field Service Version 12.2.3-12.2.15",
                                            "product_id": "P-747V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:field_service:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Field Service"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Financials Common Country Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Financials Common Country Version 12.2.3-12.2.15",
                                            "product_id": "P-375V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financials_common_country:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Financials Common Country"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Financials Common Modules Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Financials Common Modules Version 12.2.3-12.2.15",
                                            "product_id": "P-1320V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financials_common_modules:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Financials Common Modules"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Financials for the Americas Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Financials for the Americas Version 12.2.3-12.2.15",
                                            "product_id": "P-918V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financials_for_the_americas:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Financials for the Americas"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Flow Manufacturing Version 12.2.13-12.2.15",
                                        "product": {
                                            "name": "Oracle Flow Manufacturing Version 12.2.13-12.2.15",
                                            "product_id": "P-300V-12.2.13-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:flow_manufacturing:12.2.13-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Flow Manufacturing Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Flow Manufacturing Version 12.2.3-12.2.15",
                                            "product_id": "P-300V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:flow_manufacturing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Flow Manufacturing Version 12.2.7-12.2.15",
                                        "product": {
                                            "name": "Oracle Flow Manufacturing Version 12.2.7-12.2.15",
                                            "product_id": "P-300V-12.2.7-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:flow_manufacturing:12.2.7-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Flow Manufacturing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle General Ledger Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle General Ledger Version 12.2.3-12.2.15",
                                            "product_id": "P-500V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:general_ledger:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle General Ledger"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HCM Common Architecture Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HCM Common Architecture Version 12.2.3-12.2.15",
                                            "product_id": "P-2021V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hcm_common_architecture:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HCM Common Architecture"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HCM Configuration Workbench Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HCM Configuration Workbench Version 12.2.3-12.2.15",
                                            "product_id": "P-2011V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hcm_configuration_workbench:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HCM Configuration Workbench"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (France) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (France) Version 12.2.3-12.2.15",
                                            "product_id": "P-998V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (France)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (Hong Kong) Version 12.2.13-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (Hong Kong) Version 12.2.13-12.2.15",
                                            "product_id": "P-1569V-12.2.13-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.13-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (Hong Kong)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (Ireland) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (Ireland) Version 12.2.3-12.2.15",
                                            "product_id": "P-1166V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (Ireland)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (Japanese) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (Japanese) Version 12.2.3-12.2.15",
                                            "product_id": "P-699V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (Japanese)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (New Zealand) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (New Zealand) Version 12.2.3-12.2.15",
                                            "product_id": "P-1570V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (New Zealand)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (Norway) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (Norway) Version 12.2.3-12.2.15",
                                            "product_id": "P-1645V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (Norway) Version 12.2.8-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (Norway) Version 12.2.8-12.2.15",
                                            "product_id": "P-1645V-12.2.8-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.8-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (Norway)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (Republic of Korea) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (Republic of Korea) Version 12.2.3-12.2.15",
                                            "product_id": "P-1565V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (Republic of Korea)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (UK) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (UK) Version 12.2.3-12.2.15",
                                            "product_id": "P-1001V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (UK) Version 12.2.8-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (UK) Version 12.2.8-12.2.15",
                                            "product_id": "P-1001V-12.2.8-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.8-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (UK) Version 12.2.9-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (UK) Version 12.2.9-12.2.15",
                                            "product_id": "P-1001V-12.2.9-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.9-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (UK)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (US) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (US) Version 12.2.3-12.2.15",
                                            "product_id": "P-1000V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (US) Version 12.2.6-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (US) Version 12.2.6-12.2.15",
                                            "product_id": "P-1000V-12.2.6-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.6-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (US) Version 12.2.7-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (US) Version 12.2.7-12.2.15",
                                            "product_id": "P-1000V-12.2.7-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.7-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle HRMS (US) Version 12.2.9-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (US) Version 12.2.9-12.2.15",
                                            "product_id": "P-1000V-12.2.9-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.9-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (US)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Human Resources Version 12.2.14-12.2.15",
                                        "product": {
                                            "name": "Oracle Human Resources Version 12.2.14-12.2.15",
                                            "product_id": "P-507V-12.2.14-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:human_resources:12.2.14-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Human Resources Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Human Resources Version 12.2.3-12.2.15",
                                            "product_id": "P-507V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:human_resources:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Human Resources"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle In-Memory Cost Management for Discrete Industries Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle In-Memory Cost Management for Discrete Industries Version 12.2.3-12.2.15",
                                            "product_id": "P-10650V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:in-memory_cost_management_for_discrete_industries:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle In-Memory Cost Management for Discrete Industries"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Installed Base Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Installed Base Version 12.2.3-12.2.15",
                                            "product_id": "P-1118V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:installed_base:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Installed Base Version 12.2.4-12.2.15",
                                        "product": {
                                            "name": "Oracle Installed Base Version 12.2.4-12.2.15",
                                            "product_id": "P-1118V-12.2.4-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:installed_base:12.2.4-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Installed Base"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Interaction Blending Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Interaction Blending Version 12.2.3-12.2.15",
                                            "product_id": "P-182V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:interaction_blending:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Interaction Blending"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Inventory Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Inventory Management Version 12.2.3-12.2.15",
                                            "product_id": "P-508V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:inventory_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Inventory Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Inventory Optimization Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Inventory Optimization Version 12.2.3-12.2.15",
                                            "product_id": "P-1067V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:inventory_optimization:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Inventory Optimization"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Item Master Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Item Master Version 12.2.3-12.2.15",
                                            "product_id": "P-1739V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:item_master:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Item Master"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Knowledge Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Knowledge Management Version 12.2.3-12.2.15",
                                            "product_id": "P-1351V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:knowledge_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Knowledge Management Version 12.2.5-12.2.15",
                                        "product": {
                                            "name": "Oracle Knowledge Management Version 12.2.5-12.2.15",
                                            "product_id": "P-1351V-12.2.5-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:knowledge_management:12.2.5-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Knowledge Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Labor Distribution Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Labor Distribution Version 12.2.3-12.2.15",
                                            "product_id": "P-326V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:labor_distribution:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Labor Distribution"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Landed Cost Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Landed Cost Management Version 12.2.3-12.2.15",
                                            "product_id": "P-4568V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:landed_cost_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Landed Cost Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Learning Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Learning Management Version 12.2.3-12.2.15",
                                            "product_id": "P-937V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:learning_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Learning Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Lease and Finance Management Version 12.2.11-12.2.15",
                                        "product": {
                                            "name": "Oracle Lease and Finance Management Version 12.2.11-12.2.15",
                                            "product_id": "P-1056V-12.2.11-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:lease_and_finance_management:12.2.11-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Lease and Finance Management Version 12.2.14-12.2.15",
                                        "product": {
                                            "name": "Oracle Lease and Finance Management Version 12.2.14-12.2.15",
                                            "product_id": "P-1056V-12.2.14-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:lease_and_finance_management:12.2.14-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Lease and Finance Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Lease and Finance Management Version 12.2.3-12.2.15",
                                            "product_id": "P-1056V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:lease_and_finance_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Lease and Finance Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Loans Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Loans Version 12.2.3-12.2.15",
                                            "product_id": "P-1537V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:loans:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Loans"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle MES for Process Manufacturing Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle MES for Process Manufacturing Version 12.2.3-12.2.15",
                                            "product_id": "P-1776V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mes_for_process_manufacturing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle MES for Process Manufacturing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Marketing Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Marketing Version 12.2.3-12.2.15",
                                            "product_id": "P-229V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:marketing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Marketing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Mobile Application Server Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Mobile Application Server Version 12.2.3-12.2.15",
                                            "product_id": "P-995V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mobile_application_server:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Mobile Application Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Order Entry Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Order Entry Version 12.2.3-12.2.15",
                                            "product_id": "P-513V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:order_entry:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Order Entry"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Order Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Order Management Version 12.2.3-12.2.15",
                                            "product_id": "P-497V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:order_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Order Management Version 12.2.4-12.2.15",
                                        "product": {
                                            "name": "Oracle Order Management Version 12.2.4-12.2.15",
                                            "product_id": "P-497V-12.2.4-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:order_management:12.2.4-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Order Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Partner Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Partner Management Version 12.2.3-12.2.15",
                                            "product_id": "P-1065V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:partner_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Partner Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Payables Version 12.2.8-12.2.15",
                                        "product": {
                                            "name": "Oracle Payables Version 12.2.8-12.2.15",
                                            "product_id": "P-501V-12.2.8-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:payables:12.2.8-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Payables"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Payments Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Payments Version 12.2.3-12.2.15",
                                            "product_id": "P-378V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:payments:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Payments"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Payroll Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Payroll Version 12.2.3-12.2.15",
                                            "product_id": "P-506V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:payroll:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Payroll"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Performance Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Performance Management Version 12.2.3-12.2.15",
                                            "product_id": "P-4425V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:performance_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Performance Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Price Protection Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Price Protection Version 12.2.3-12.2.15",
                                            "product_id": "P-4347V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:price_protection:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Price Protection"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Process Manufacturing Financials Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Financials Version 12.2.3-12.2.15",
                                            "product_id": "P-736V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_financials:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Process Manufacturing Financials"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Process Manufacturing Inventory Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Inventory Version 12.2.3-12.2.15",
                                            "product_id": "P-733V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_inventory:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Process Manufacturing Inventory"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Process Manufacturing Logistics Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Logistics Version 12.2.3-12.2.15",
                                            "product_id": "P-740V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_logistics:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Process Manufacturing Logistics"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Process Manufacturing Process Execution Version 12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Process Execution Version 12.2.15",
                                            "product_id": "P-742V-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_process_execution:12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Process Manufacturing Process Execution"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Process Manufacturing Product Development Version 12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Product Development Version 12.2.15",
                                            "product_id": "P-744V-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_product_development:12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Process Manufacturing Product Development Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Product Development Version 12.2.3-12.2.15",
                                            "product_id": "P-744V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_product_development:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Process Manufacturing Product Development"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Process Manufacturing Regulatory Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Regulatory Management Version 12.2.3-12.2.15",
                                            "product_id": "P-280V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_regulatory_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Process Manufacturing Regulatory Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Process Manufacturing Systems Version 12.2.11-12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Systems Version 12.2.11-12.2.15",
                                            "product_id": "P-743V-12.2.11-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_systems:12.2.11-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Process Manufacturing Systems Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Systems Version 12.2.3-12.2.15",
                                            "product_id": "P-743V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_systems:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Process Manufacturing Systems"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Product Hub Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Product Hub Version 12.2.3-12.2.15",
                                            "product_id": "P-1313V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:product_hub:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Product Hub"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Product Workbench Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Product Workbench Version 12.2.3-12.2.15",
                                            "product_id": "P-1597V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:product_workbench:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Product Workbench"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Production Scheduling Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Production Scheduling Version 12.2.3-12.2.15",
                                            "product_id": "P-1983V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:production_scheduling:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Production Scheduling"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Project Contracts Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Project Contracts Version 12.2.3-12.2.15",
                                            "product_id": "P-799V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:project_contracts:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Project Contracts"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Project Costing Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Project Costing Version 12.2.3-12.2.15",
                                            "product_id": "P-1287V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:project_costing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Project Costing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Project Foundation Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Project Foundation Version 12.2.3-12.2.15",
                                            "product_id": "P-1293V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:project_foundation:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Project Foundation"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Project Intelligence Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Project Intelligence Version 12.2.3-12.2.15",
                                            "product_id": "P-1292V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:project_intelligence:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Project Intelligence"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Project Manufacturing Version V16",
                                        "product": {
                                            "name": "Oracle Project Manufacturing Version V16",
                                            "product_id": "P-321V-V16",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:project_manufacturing:v16:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Project Manufacturing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Project Portfolio Analysis Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Project Portfolio Analysis Version 12.2.3-12.2.15",
                                            "product_id": "P-1358V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:project_portfolio_analysis:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Project Portfolio Analysis"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Property Manager Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Property Manager Version 12.2.3-12.2.15",
                                            "product_id": "P-44V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:property_manager:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Property Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Proposals Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Proposals Version 12.2.3-12.2.15",
                                            "product_id": "P-1333V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:proposals:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Proposals"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Public Sector Financials Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Public Sector Financials Version 12.2.3-12.2.15",
                                            "product_id": "P-485V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:public_sector_financials:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Public Sector Financials"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Public Sector Financials (International) Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Public Sector Financials (International) Version 12.2.3-12.2.15",
                                            "product_id": "P-26V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:public_sector_financials:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Public Sector Financials (International)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Public Sector Human Resources Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Public Sector Human Resources Version 12.2.3-12.2.15",
                                            "product_id": "P-210V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:public_sector_human_resources:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Public Sector Human Resources"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Public Sector Payroll Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Public Sector Payroll Version 12.2.3-12.2.15",
                                            "product_id": "P-196V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:public_sector_payroll:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Public Sector Payroll Version 12.2.4-12.2.15",
                                        "product": {
                                            "name": "Oracle Public Sector Payroll Version 12.2.4-12.2.15",
                                            "product_id": "P-196V-12.2.4-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:public_sector_payroll:12.2.4-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Public Sector Payroll"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Purchasing Version 12.2.11-12.2.15",
                                        "product": {
                                            "name": "Oracle Purchasing Version 12.2.11-12.2.15",
                                            "product_id": "P-502V-12.2.11-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:purchasing:12.2.11-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Purchasing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Quality Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Quality Version 12.2.3-12.2.15",
                                            "product_id": "P-214V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:quality:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Quality"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Quoting Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Quoting Version 12.2.3-12.2.15",
                                            "product_id": "P-1296V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:quoting:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Quoting"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Receivables Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Receivables Version 12.2.3-12.2.15",
                                            "product_id": "P-505V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:receivables:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Receivables"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Risk Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Risk Management Version 12.2.3-12.2.15",
                                            "product_id": "P-1172V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:risk_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Risk Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle SDP Number Portability Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle SDP Number Portability Version 12.2.3-12.2.15",
                                            "product_id": "P-217V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sdp_number_portability:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle SDP Number Portability"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Sales Offline Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Sales Offline Version 12.2.3-12.2.15",
                                            "product_id": "P-1009V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sales_offline:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Sales Offline"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Sales for Handhelds Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Sales for Handhelds Version 12.2.3-12.2.15",
                                            "product_id": "P-186V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sales_for_handhelds:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Sales for Handhelds"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Scheduler Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Scheduler Version 12.2.3-12.2.15",
                                            "product_id": "P-756V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:scheduler:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Scheduler"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Scripting Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Scripting Version 12.2.3-12.2.15",
                                            "product_id": "P-433V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:scripting:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Scripting"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Self-Service Human Resources Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Self-Service Human Resources Version 12.2.3-12.2.15",
                                            "product_id": "P-1566V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:self-service_human_resources:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Self-Service Human Resources"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Service Contracts Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Service Contracts Version 12.2.3-12.2.15",
                                            "product_id": "P-432V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:service_contracts:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Service Contracts"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Service Fulfillment Manager Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Service Fulfillment Manager Version 12.2.3-12.2.15",
                                            "product_id": "P-129V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:service_fulfillment_manager:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Service Fulfillment Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Shipping Execution Version 12.2.12-12.2.15",
                                        "product": {
                                            "name": "Oracle Shipping Execution Version 12.2.12-12.2.15",
                                            "product_id": "P-996V-12.2.12-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:shipping_execution:12.2.12-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Shipping Execution"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Site Hub Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Site Hub Version 12.2.3-12.2.15",
                                            "product_id": "P-1676V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:site_hub:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Site Hub"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Succession planning Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Succession planning Version 12.2.3-12.2.15",
                                            "product_id": "P-5709V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:succession_planning:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Succession planning"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Supply Chain Globalization Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Supply Chain Globalization Version 12.2.3-12.2.15",
                                            "product_id": "P-29V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:supply_chain_globalization:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Supply Chain Globalization"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Supply Chain Trading Connector Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Supply Chain Trading Connector Version 12.2.3-12.2.15",
                                            "product_id": "P-1311V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:supply_chain_trading_connector:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Supply Chain Trading Connector"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle TeleSales Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle TeleSales Version 12.2.3-12.2.15",
                                            "product_id": "P-296V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:telesales:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle TeleSales"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Telecommunications Billing Integrator Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Telecommunications Billing Integrator Version 12.2.3-12.2.15",
                                            "product_id": "P-1300V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:telecommunications_billing_integrator:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Telecommunications Billing Integrator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Teleservice Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Teleservice Version 12.2.3-12.2.15",
                                            "product_id": "P-543V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:teleservice:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Teleservice"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Time and Labor Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Time and Labor Version 12.2.3-12.2.15",
                                            "product_id": "P-311V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:time_and_labor:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Time and Labor"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Trade Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Trade Management Version 12.2.3-12.2.15",
                                            "product_id": "P-765V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:trade_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Trade Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Trading Community Version 12.2.3-12.2.12",
                                        "product": {
                                            "name": "Oracle Trading Community Version 12.2.3-12.2.12",
                                            "product_id": "P-1137V-12.2.3-12.2.12",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:trading_community:12.2.3-12.2.12:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Trading Community Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Trading Community Version 12.2.3-12.2.15",
                                            "product_id": "P-1137V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:trading_community:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Trading Community"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Transportation Execution Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Transportation Execution Version 12.2.3-12.2.15",
                                            "product_id": "P-1060V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:transportation_execution:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Transportation Execution"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Treasury Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Treasury Version 12.2.3-12.2.15",
                                            "product_id": "P-512V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:treasury:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Treasury"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle U.S. Federal Financials Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle U.S. Federal Financials Version 12.2.3-12.2.15",
                                            "product_id": "P-935V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:u.s._federal_financials:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle U.S. Federal Financials"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle US Federal Human Resources Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle US Federal Human Resources Version 12.2.3-12.2.15",
                                            "product_id": "P-899V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:us_federal_human_resources:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle US Federal Human Resources"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Universal Work Queue Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Universal Work Queue Version 12.2.3-12.2.15",
                                            "product_id": "P-778V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:universal_work_queue:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Universal Work Queue"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Warehouse Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Warehouse Management Version 12.2.3-12.2.15",
                                            "product_id": "P-385V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:warehouse_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Warehouse Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Work in Process Version 12.2.14-12.2.15",
                                        "product": {
                                            "name": "Oracle Work in Process Version 12.2.14-12.2.15",
                                            "product_id": "P-572V-12.2.14-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:work_in_process:12.2.14-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Work in Process Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Work in Process Version 12.2.3-12.2.15",
                                            "product_id": "P-572V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:work_in_process:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Work in Process Version 12.2.5-12.2.15",
                                        "product": {
                                            "name": "Oracle Work in Process Version 12.2.5-12.2.15",
                                            "product_id": "P-572V-12.2.5-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:work_in_process:12.2.5-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Work in Process"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Workflow Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Workflow Version 12.2.3-12.2.15",
                                            "product_id": "P-174V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:workflow:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Workflow"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Yard Management Version 12.2.6-12.2.15",
                                        "product": {
                                            "name": "Oracle Yard Management Version 12.2.6-12.2.15",
                                            "product_id": "P-10485V-12.2.6-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:yard_management:12.2.6-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Yard Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle iReceivables Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle iReceivables Version 12.2.3-12.2.15",
                                            "product_id": "P-1106V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:ireceivables:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle iReceivables"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle iRecruitment Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle iRecruitment Version 12.2.3-12.2.15",
                                            "product_id": "P-1193V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:irecruitment:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle iRecruitment"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle iSetup Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle iSetup Version 12.2.3-12.2.15",
                                            "product_id": "P-841V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:isetup:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle iSetup"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle iStore Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle iStore Version 12.2.3-12.2.15",
                                            "product_id": "P-384V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:istore:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle iStore"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle iSupplier Portal Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle iSupplier Portal Version 12.2.3-12.2.15",
                                            "product_id": "P-208V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:isupplier_portal:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle iSupplier Portal"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle iSupport Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle iSupport Version 12.2.3-12.2.15",
                                            "product_id": "P-381V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:isupport:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle iSupport"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Pasta Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Pasta Version 12.2.3-12.2.15",
                                            "product_id": "P-1195V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:pasta:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Pasta"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle E-Business Suite"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Manager Base Platform Version 13.5",
                                        "product": {
                                            "name": "Oracle Enterprise Manager Base Platform Version 13.5",
                                            "product_id": "P-1370V-13.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Manager Base Platform Version 24.1",
                                        "product": {
                                            "name": "Oracle Enterprise Manager Base Platform Version 24.1",
                                            "product_id": "P-1370V-24.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Manager Base Platform"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Manager for Fusion Middleware(Oracle Enterprise Manager for Fusion Middleware_Web Services Management) Version 13.5",
                                        "product": {
                                            "name": "Oracle Enterprise Manager for Fusion Middleware(Oracle Enterprise Manager for Fusion Middleware_Web Services Management) Version 13.5",
                                            "product_id": "P-1369(Oracle Enterprise Manager for Fusion Middleware_Web Services Management)V-13.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:13.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Manager for Fusion Middleware"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Enterprise Manager for MySQL Database Version 13.5.4.0.0-13.5.5.0.0",
                                        "product": {
                                            "name": "Oracle Enterprise Manager for MySQL Database Version 13.5.4.0.0-13.5.5.0.0",
                                            "product_id": "P-11166V-13.5.4.0.0-13.5.5.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_for_mysql_database:13.5.4.0.0-13.5.5.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Manager for MySQL Database"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Enterprise Manager"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Essbase Version 21.8.1.0.0",
                                        "product": {
                                            "name": "Oracle Essbase Version 21.8.1.0.0",
                                            "product_id": "P-4379V-21.8.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:essbase:21.8.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Essbase"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Essbase"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Corporate Lending Process Management Version 14.6.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Corporate Lending Process Management Version 14.6.0-14.8.0",
                                            "product_id": "P-13701V-14.6.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.6.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Corporate Lending Process Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Liquidity Management Version 14.5.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Liquidity Management Version 14.5.0-14.8.0",
                                            "product_id": "P-13304V-14.5.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.5.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Liquidity Management Version 14.6.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Liquidity Management Version 14.6.0-14.8.0",
                                            "product_id": "P-13304V-14.6.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.6.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Liquidity Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Origination Version 14.5.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Origination Version 14.5.0-14.8.0",
                                            "product_id": "P-14325V-14.5.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_origination:14.5.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Banking Origination Version 14.5.0.16.0",
                                        "product": {
                                            "name": "Oracle Banking Origination Version 14.5.0.16.0",
                                            "product_id": "P-14325V-14.5.0.16.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_origination:14.5.0.16.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Origination Version 14.6.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Origination Version 14.6.0-14.8.0",
                                            "product_id": "P-14325V-14.6.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_origination:14.6.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Origination"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Payments Version 14.5.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Payments Version 14.5.0-14.8.0",
                                            "product_id": "P-13011V-14.5.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_payments:14.5.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Payments"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Trade Finance Version 14.6.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Trade Finance Version 14.6.0-14.8.0",
                                            "product_id": "P-14134V-14.6.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_trade_finance:14.6.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Trade Finance"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Trade Finance Process Management Version 14.6.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Trade Finance Process Management Version 14.6.0-14.8.0",
                                            "product_id": "P-13718V-14.6.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_trade_finance_process_management:14.6.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Trade Finance Process Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Virtual Account Management Version 14.5.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Virtual Account Management Version 14.5.0-14.8.0",
                                            "product_id": "P-13487V-14.5.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Banking Virtual Account Management Version 14.6.0-14.8.0",
                                        "product": {
                                            "name": "Oracle Banking Virtual Account Management Version 14.6.0-14.8.0",
                                            "product_id": "P-13487V-14.6.0-14.8.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_virtual_account_management:14.6.0-14.8.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Virtual Account Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.9.0",
                                        "product": {
                                            "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.9.0",
                                            "product_id": "P-5680V-8.0.7.9.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.9.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.7.0",
                                        "product": {
                                            "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.7.0",
                                            "product_id": "P-5680V-8.0.8.7.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8.7.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.5.0",
                                        "product": {
                                            "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.5.0",
                                            "product_id": "P-5680V-8.1.2.5.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.5.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Financial Services Analytical Applications Infrastructure"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Financial Services Compliance Studio Version 8.1.2.9",
                                        "product": {
                                            "name": "Oracle Financial Services Compliance Studio Version 8.1.2.9",
                                            "product_id": "P-14392V-8.1.2.9",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financial_services_compliance_studio:8.1.2.9:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Financial Services Compliance Studio Version 8.1.3.0",
                                        "product": {
                                            "name": "Oracle Financial Services Compliance Studio Version 8.1.3.0",
                                            "product_id": "P-14392V-8.1.3.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financial_services_compliance_studio:8.1.3.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Financial Services Compliance Studio Version 8.1.3.1",
                                        "product": {
                                            "name": "Oracle Financial Services Compliance Studio Version 8.1.3.1",
                                            "product_id": "P-14392V-8.1.3.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financial_services_compliance_studio:8.1.3.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Financial Services Compliance Studio"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Financial Services Model Management and Governance Version 8.1.2.7",
                                        "product": {
                                            "name": "Oracle Financial Services Model Management and Governance Version 8.1.2.7",
                                            "product_id": "P-14276V-8.1.2.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.2.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Financial Services Model Management and Governance"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Financial Services Applications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Hospitality Simphony Version 19.10",
                                        "product": {
                                            "name": "Oracle Hospitality Simphony Version 19.10",
                                            "product_id": "P-11594V-19.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hospitality_simphony:19.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Hospitality Simphony Version 19.8-19.8.5",
                                        "product": {
                                            "name": "Oracle Hospitality Simphony Version 19.8-19.8.5",
                                            "product_id": "P-11594V-19.8-19.8.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hospitality_simphony:19.8-19.8.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Hospitality Simphony Version 19.9-19.9.3",
                                        "product": {
                                            "name": "Oracle Hospitality Simphony Version 19.9-19.9.3",
                                            "product_id": "P-11594V-19.9-19.9.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hospitality_simphony:19.9-19.9.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Hospitality Simphony"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Food and Beverage Applications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Access Manager Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Access Manager Version 12.2.1.4.0",
                                            "product_id": "P-5565V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Access Manager Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Access Manager Version 14.1.2.1.0",
                                            "product_id": "P-5565V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Access Manager Version 15.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Access Manager Version 15.1.1.0.0",
                                            "product_id": "P-5565V-15.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:access_manager:15.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Access Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
                                            "product_id": "P-5325V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Business Process Management Suite Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Business Process Management Suite Version 14.1.2.0.0",
                                            "product_id": "P-5325V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:business_process_management_suite:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Business Process Management Suite"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Coherence Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Coherence Version 12.2.1.4.0",
                                            "product_id": "P-2545V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Coherence Version 14.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Coherence Version 14.1.1.0.0",
                                            "product_id": "P-2545V-14.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Coherence Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Coherence Version 14.1.2.0.0",
                                            "product_id": "P-2545V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Coherence Version 15.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Coherence Version 15.1.1.0.0",
                                            "product_id": "P-2545V-15.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Coherence"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Data Integrator Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Data Integrator Version 12.2.1.4.0",
                                            "product_id": "P-2196V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Data Integrator Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Data Integrator Version 14.1.2.0.0",
                                            "product_id": "P-2196V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Data Integrator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Data Quality Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Enterprise Data Quality Version 12.2.1.4.0",
                                            "product_id": "P-9464V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_data_quality:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Data Quality Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Enterprise Data Quality Version 14.1.2.0.0",
                                            "product_id": "P-9464V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_data_quality:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Data Quality"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Fusion Middleware Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Fusion Middleware Version 12.2.1.4.0",
                                            "product_id": "P-1032V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Fusion Middleware Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Fusion Middleware Version 14.1.2.0.0",
                                            "product_id": "P-1032V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:fusion_middleware:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Fusion Middleware"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 12.2.1.4.0",
                                            "product_id": "P-12738V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.1.0.0",
                                            "product_id": "P-12738V-14.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:14.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.2.0.0",
                                            "product_id": "P-12738V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.2.1.0",
                                            "product_id": "P-12738V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 15.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 15.1.1.0.0",
                                            "product_id": "P-12738V-15.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:15.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Global Lifecycle Management NextGen OUI Framework"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_Apache Plugin) Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_Apache Plugin) Version 12.2.1.4.0",
                                            "product_id": "P-1042(Oracle HTTP Server_Apache Plugin)V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_Core) Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_Core) Version 12.2.1.4.0",
                                            "product_id": "P-1042(Oracle HTTP Server_Core)V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server) Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server) Version 12.2.1.4.0",
                                            "product_id": "P-1042(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server)V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_mod_proxy) Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_mod_proxy) Version 12.2.1.4.0",
                                            "product_id": "P-1042(Oracle HTTP Server_mod_proxy)V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_mod_ssl) Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_mod_ssl) Version 12.2.1.4.0",
                                            "product_id": "P-1042(Oracle HTTP Server_mod_ssl)V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_Apache Plugin) Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_Apache Plugin) Version 14.1.2.0.0",
                                            "product_id": "P-1042(Oracle HTTP Server_Apache Plugin)V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_Core) Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_Core) Version 14.1.2.0.0",
                                            "product_id": "P-1042(Oracle HTTP Server_Core)V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server) Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server) Version 14.1.2.0.0",
                                            "product_id": "P-1042(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server)V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_mod_http2.so) Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_mod_http2.so) Version 14.1.2.0.0",
                                            "product_id": "P-1042(Oracle HTTP Server_mod_http2.so)V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_mod_proxy) Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_mod_proxy) Version 14.1.2.0.0",
                                            "product_id": "P-1042(Oracle HTTP Server_mod_proxy)V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle HTTP Server(Oracle HTTP Server_mod_ssl) Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle HTTP Server(Oracle HTTP Server_mod_ssl) Version 14.1.2.0.0",
                                            "product_id": "P-1042(Oracle HTTP Server_mod_ssl)V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HTTP Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Identity Manager Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Identity Manager Version 12.2.1.4.0",
                                            "product_id": "P-1980V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Identity Manager Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Identity Manager Version 14.1.2.1.0",
                                            "product_id": "P-1980V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Identity Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Identity Manager Connector Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Identity Manager Connector Version 12.2.1.4.0",
                                            "product_id": "P-1999V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Identity Manager Connector Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Identity Manager Connector Version 14.1.2.1.0",
                                            "product_id": "P-1999V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Identity Manager Connector"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle JDeveloper Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle JDeveloper Version 12.2.1.4.0",
                                            "product_id": "P-807V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle JDeveloper Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle JDeveloper Version 14.1.2.0.0",
                                            "product_id": "P-807V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle JDeveloper"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                                            "product_id": "P-10198V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Managed File Transfer Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Managed File Transfer Version 14.1.2.0.0",
                                            "product_id": "P-10198V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:managed_file_transfer:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Managed File Transfer"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                                            "product_id": "P-4647V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                                            "product_id": "P-4647V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Middleware Common Libraries and Tools"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Platform Security for Java Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Platform Security for Java Version 12.2.1.4.0",
                                            "product_id": "P-2233V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:platform_security_for_java:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Platform Security for Java Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Platform Security for Java Version 14.1.2.0.0",
                                            "product_id": "P-2233V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:platform_security_for_java:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Platform Security for Java"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle SOA Suite Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle SOA Suite Version 12.2.1.4.0",
                                            "product_id": "P-1162V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:soa_suite:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle SOA Suite Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle SOA Suite Version 14.1.2.0.0",
                                            "product_id": "P-1162V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:soa_suite:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle SOA Suite"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Security Service Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Security Service Version 12.2.1.4.0",
                                            "product_id": "P-991V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:security_service:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Security Service"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Unified Directory Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Unified Directory Version 12.2.1.4.0",
                                            "product_id": "P-9118V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Unified Directory Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Unified Directory Version 14.1.2.1.0",
                                            "product_id": "P-9118V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Unified Directory"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Content Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebCenter Content Version 12.2.1.4.0",
                                            "product_id": "P-2271V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Content Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebCenter Content Version 14.1.2.0.0",
                                            "product_id": "P-2271V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebCenter Content"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Enterprise Capture Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebCenter Enterprise Capture Version 12.2.1.4.0",
                                            "product_id": "P-10212V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Enterprise Capture Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebCenter Enterprise Capture Version 14.1.2.0.0",
                                            "product_id": "P-10212V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebCenter Enterprise Capture"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                                            "product_id": "P-1696V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Portal Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebCenter Portal Version 14.1.2.0.0",
                                            "product_id": "P-1696V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebCenter Portal"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Sites Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebCenter Sites Version 12.2.1.4.0",
                                            "product_id": "P-9617V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Sites Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebCenter Sites Version 14.1.2.0.0",
                                            "product_id": "P-9617V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebCenter Sites"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                                            "product_id": "P-5242V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                                        "product": {
                                            "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                                            "product_id": "P-5242V-14.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                                            "product_id": "P-5242V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebLogic Server Version 15.1.1.0.0",
                                        "product": {
                                            "name": "Oracle WebLogic Server Version 15.1.1.0.0",
                                            "product_id": "P-5242V-15.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebLogic Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers) Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers) Version 12.2.1.4.0",
                                            "product_id": "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers) Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers) Version 14.1.2.0.0",
                                            "product_id": "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers) Version 15.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers) Version 15.1.1.0.0",
                                            "product_id": "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-15.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:15.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Weblogic Server Proxy Plug-in"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Service Delivery Platform Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Service Delivery Platform Version 12.2.1.4.0",
                                            "product_id": "P-2063V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Service Delivery Platform Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Service Delivery Platform Version 14.1.2.0.0",
                                            "product_id": "P-2063V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Service Delivery Platform"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "WebCenter Content: Imaging Version 12.2.1.4.0",
                                        "product": {
                                            "name": "WebCenter Content: Imaging Version 12.2.1.4.0",
                                            "product_id": "P-4576V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "WebCenter Content: Imaging Version 14.1.2.0.0",
                                        "product": {
                                            "name": "WebCenter Content: Imaging Version 14.1.2.0.0",
                                            "product_id": "P-4576V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "WebCenter Content: Imaging"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Fusion Middleware"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "OPatch Version 12.2.0.1.16-12.2.0.1.51",
                                        "product": {
                                            "name": "OPatch Version 12.2.0.1.16-12.2.0.1.51",
                                            "product_id": "P-12753V-12.2.0.1.16-12.2.0.1.51",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:opatch:12.2.0.1.16-12.2.0.1.51:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "OPatch"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Global Lifecycle Management"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "GoldenGate Stream Analytics(GoldenGate Stream Analytics_Security) Version 19.1.0.0.0-19.1.0.0.15",
                                        "product": {
                                            "name": "GoldenGate Stream Analytics(GoldenGate Stream Analytics_Security) Version 19.1.0.0.0-19.1.0.0.15",
                                            "product_id": "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:19.1.0.0.0-19.1.0.0.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "GoldenGate Stream Analytics(GoldenGate Stream Analytics_Third Party) Version 19.1.0.0.0-19.1.0.0.15",
                                        "product": {
                                            "name": "GoldenGate Stream Analytics(GoldenGate Stream Analytics_Third Party) Version 19.1.0.0.0-19.1.0.0.15",
                                            "product_id": "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:19.1.0.0.0-19.1.0.0.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "GoldenGate Stream Analytics(GoldenGate Stream Analytics_Security) Version 26.1.0.0.0",
                                        "product": {
                                            "name": "GoldenGate Stream Analytics(GoldenGate Stream Analytics_Security) Version 26.1.0.0.0",
                                            "product_id": "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:26.1.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "GoldenGate Stream Analytics"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Version 19.1.0.0.0-19.29.0.0",
                                        "product": {
                                            "name": "Oracle GoldenGate Version 19.1.0.0.0-19.29.0.0",
                                            "product_id": "P-5757V-19.1.0.0.0-19.29.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate:19.1.0.0.0-19.29.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Version 19.1.0.0.0-19.30.0.0",
                                        "product": {
                                            "name": "Oracle GoldenGate Version 19.1.0.0.0-19.30.0.0",
                                            "product_id": "P-5757V-19.1.0.0.0-19.30.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate:19.1.0.0.0-19.30.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Version 21.3-21.21",
                                        "product": {
                                            "name": "Oracle GoldenGate Version 21.3-21.21",
                                            "product_id": "P-5757V-21.3-21.21",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate:21.3-21.21:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Version 23.4-23.26.1",
                                        "product": {
                                            "name": "Oracle GoldenGate Version 23.4-23.26.1",
                                            "product_id": "P-5757V-23.4-23.26.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate:23.4-23.26.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Version 23.4-23.26.1.0.0",
                                        "product": {
                                            "name": "Oracle GoldenGate Version 23.4-23.26.1.0.0",
                                            "product_id": "P-5757V-23.4-23.26.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate:23.4-23.26.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Version 23.4-23.26.2",
                                        "product": {
                                            "name": "Oracle GoldenGate Version 23.4-23.26.2",
                                            "product_id": "P-5757V-23.4-23.26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate:23.4-23.26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GoldenGate"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Big Data and Application Adapters Version 19.1.0.0.0-19.1.0.0.22",
                                        "product": {
                                            "name": "Oracle GoldenGate Big Data and Application Adapters Version 19.1.0.0.0-19.1.0.0.22",
                                            "product_id": "P-5760V-19.1.0.0.0-19.1.0.0.22",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:19.1.0.0.0-19.1.0.0.22:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.20",
                                        "product": {
                                            "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.20",
                                            "product_id": "P-5760V-21.3-21.20",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:21.3-21.20:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.26.1",
                                        "product": {
                                            "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.26.1",
                                            "product_id": "P-5760V-23.4-23.26.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:23.4-23.26.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GoldenGate Big Data and Application Adapters"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Studio Version 23.8.0-23.26.1",
                                        "product": {
                                            "name": "Oracle GoldenGate Studio Version 23.8.0-23.26.1",
                                            "product_id": "P-10945V-23.8.0-23.26.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate_studio:23.8.0-23.26.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GoldenGate Studio"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle GoldenGate Veridata Version 23.1.0.0.0-23.26.1.0.0.0",
                                        "product": {
                                            "name": "Oracle GoldenGate Veridata Version 23.1.0.0.0-23.26.1.0.0.0",
                                            "product_id": "P-5758V-23.1.0.0.0-23.26.1.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:goldengate_veridata:23.1.0.0.0-23.26.1.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GoldenGate Veridata"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle GoldenGate"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Graph Server and Client Version 25.4.1",
                                        "product": {
                                            "name": "Oracle Graph Server and Client Version 25.4.1",
                                            "product_id": "P-14069V-25.4.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graph_server_and_client:25.4.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Graph Server and Client Version 25.4.2",
                                        "product": {
                                            "name": "Oracle Graph Server and Client Version 25.4.2",
                                            "product_id": "P-14069V-25.4.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graph_server_and_client:25.4.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Graph Server and Client Version 26.1.0",
                                        "product": {
                                            "name": "Oracle Graph Server and Client Version 26.1.0",
                                            "product_id": "P-14069V-26.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graph_server_and_client:26.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Graph Server and Client"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Graph Server and Client"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Health Sciences Information Manager Version 4.0.0-4.0.2",
                                        "product": {
                                            "name": "Oracle Health Sciences Information Manager Version 4.0.0-4.0.2",
                                            "product_id": "P-9177V-4.0.0-4.0.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:health_sciences_information_manager:4.0.0-4.0.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Health Sciences Information Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Healthcare Data Repository Version 8.2.0.0-8.2.0.7",
                                        "product": {
                                            "name": "Oracle Healthcare Data Repository Version 8.2.0.0-8.2.0.7",
                                            "product_id": "P-9161V-8.2.0.0-8.2.0.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:healthcare_data_repository:8.2.0.0-8.2.0.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Healthcare Data Repository"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Healthcare Master Person Index Version 5.0.0.0-5.0.9.6",
                                        "product": {
                                            "name": "Oracle Healthcare Master Person Index Version 5.0.0.0-5.0.9.6",
                                            "product_id": "P-8575V-5.0.0.0-5.0.9.6",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:healthcare_master_person_index:5.0.0.0-5.0.9.6:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Healthcare Master Person Index"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle HealthCare Applications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Hospitality Cruise Shipboard Property Management (SPMS) Version 23.1",
                                        "product": {
                                            "name": "Oracle Hospitality Cruise Shipboard Property Management (SPMS) Version 23.1",
                                            "product_id": "P-11705V-23.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management:23.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Hospitality Cruise Shipboard Property Management (SPMS) Version 23.2",
                                        "product": {
                                            "name": "Oracle Hospitality Cruise Shipboard Property Management (SPMS) Version 23.2",
                                            "product_id": "P-11705V-23.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management:23.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Hospitality Cruise Shipboard Property Management (SPMS)"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Hospitality Applications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne Advanced Pricing - Procurement Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne Advanced Pricing - Procurement Version 9.2",
                                            "product_id": "P-4694V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_advanced_pricing_-_procurement:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne Advanced Pricing - Procurement"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne CRM Foundation Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne CRM Foundation Version 9.2",
                                            "product_id": "P-4717V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_crm_foundation:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne CRM Foundation"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne Configurator Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne Configurator Version 9.2",
                                            "product_id": "P-4710V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_configurator:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne Configurator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne General Ledger Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne General Ledger Version 9.2",
                                            "product_id": "P-4737V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_general_ledger:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne General Ledger"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne HCM Foundation Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne HCM Foundation Version 9.2",
                                            "product_id": "P-4740V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_hcm_foundation:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne HCM Foundation"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne Human Resources Management Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne Human Resources Management Version 9.2",
                                            "product_id": "P-4742V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_human_resources_management:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne Human Resources Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne Procurement and Subcontract Management Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne Procurement and Subcontract Management Version 9.2",
                                            "product_id": "P-4753V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_procurement_and_subcontract_management:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne Procurement and Subcontract Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne Requirements Planning Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne Requirements Planning Version 9.2",
                                            "product_id": "P-4763V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_requirements_planning:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne Requirements Planning"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne Solution Advisor Version 9.2",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne Solution Advisor Version 9.2",
                                            "product_id": "P-4775V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_solution_advisor:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne Solution Advisor"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "JD Edwards EnterpriseOne Tools Version 9.2.26.3",
                                        "product": {
                                            "name": "JD Edwards EnterpriseOne Tools Version 9.2.26.3",
                                            "product_id": "P-4781V-9.2.26.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.26.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "JD Edwards EnterpriseOne Tools"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle JD Edwards"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle GraalVM Enterprise Edition Version 21.3.18",
                                        "product": {
                                            "name": "Oracle GraalVM Enterprise Edition Version 21.3.18",
                                            "product_id": "P-13497V-21.3.18",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GraalVM Enterprise Edition"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle GraalVM for JDK Version 17.0.19",
                                        "product": {
                                            "name": "Oracle GraalVM for JDK Version 17.0.19",
                                            "product_id": "P-13497V-17.0.19",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle GraalVM for JDK Version 21.0.11",
                                        "product": {
                                            "name": "Oracle GraalVM for JDK Version 21.0.11",
                                            "product_id": "P-13497V-21.0.11",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GraalVM for JDK"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version 11.0.31",
                                        "product": {
                                            "name": "Oracle Java SE Version 11.0.31",
                                            "product_id": "P-856V-11.0.31",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:11.0.31:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version 17.0.19",
                                        "product": {
                                            "name": "Oracle Java SE Version 17.0.19",
                                            "product_id": "P-856V-17.0.19",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:17.0.19:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version 21.0.11",
                                        "product": {
                                            "name": "Oracle Java SE Version 21.0.11",
                                            "product_id": "P-856V-21.0.11",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:21.0.11:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version 25.0.3",
                                        "product": {
                                            "name": "Oracle Java SE Version 25.0.3",
                                            "product_id": "P-856V-25.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:25.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version 26.0.1",
                                        "product": {
                                            "name": "Oracle Java SE Version 26.0.1",
                                            "product_id": "P-856V-26.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:26.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version 8u491",
                                        "product": {
                                            "name": "Oracle Java SE Version 8u491",
                                            "product_id": "P-856V-8u491",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version 8u491-perf",
                                        "product": {
                                            "name": "Oracle Java SE Version 8u491-perf",
                                            "product_id": "P-856V-8u491-perf",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:8u491:*:*:*:enterprise_performance:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.18",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.18",
                                            "product_id": "P-13497V-Oracle GraalVM Enterprise Edition:21.3.18",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle GraalVM for JDK:17.0.19",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle GraalVM for JDK:17.0.19",
                                            "product_id": "P-13497V-Oracle GraalVM for JDK:17.0.19",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle GraalVM for JDK:21.0.11",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle GraalVM for JDK:21.0.11",
                                            "product_id": "P-13497V-Oracle GraalVM for JDK:21.0.11",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle Java SE:11.0.31",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle Java SE:11.0.31",
                                            "product_id": "P-856V-Oracle Java SE:11.0.31",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:11.0.31:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle Java SE:17.0.19",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle Java SE:17.0.19",
                                            "product_id": "P-856V-Oracle Java SE:17.0.19",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:17.0.19:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle Java SE:21.0.11",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle Java SE:21.0.11",
                                            "product_id": "P-856V-Oracle Java SE:21.0.11",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:21.0.11:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle Java SE:25.0.3",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle Java SE:25.0.3",
                                            "product_id": "P-856V-Oracle Java SE:25.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:25.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle Java SE:26.0.1",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle Java SE:26.0.1",
                                            "product_id": "P-856V-Oracle Java SE:26.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:26.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle Java SE:8u491",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle Java SE:8u491",
                                            "product_id": "P-856V-Oracle Java SE:8u491",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Java SE Version Oracle Java SE:8u491-perf",
                                        "product": {
                                            "name": "Oracle Java SE Version Oracle Java SE:8u491-perf",
                                            "product_id": "P-856V-Oracle Java SE:8u491-perf",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:java_se:8u491:*:*:*:enterprise_performance:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Java SE"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Java SE"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster_Server: Optimizer) Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster_Server: Optimizer) Version 8.0.0-8.0.47",
                                            "product_id": "P-8478(MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster Version 8.0.0-8.0.47",
                                        "product": {
                                            "name": "MySQL Cluster Version 8.0.0-8.0.47",
                                            "product_id": "P-8479V-8.0.0-8.0.47",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.47:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Cluster Version 8.4.0-8.4.10",
                                            "product_id": "P-8479V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer) Version 9.0.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer) Version 9.0.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.0.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.0.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Configurator) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Configurator) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Configurator)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: GIS) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: GIS) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: GIS)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Cluster Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Cluster Version 9.7.0-9.7.1",
                                            "product_id": "P-8479V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "MySQL Cluster"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Connectors(MySQL Connectors_Connector/C++) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Connectors(MySQL Connectors_Connector/C++) Version 9.7.0-9.7.1",
                                            "product_id": "P-8576(MySQL Connectors_Connector/C++)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_mysql_connectors_connector\\/c\\+\\+:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Connectors(MySQL Connectors_Connector/J) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Connectors(MySQL Connectors_Connector/J) Version 9.7.0-9.7.1",
                                            "product_id": "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_mysql_connectors_connector\\/j:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Connectors(MySQL Connectors_Connector/Net) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Connectors(MySQL Connectors_Connector/Net) Version 9.7.0-9.7.1",
                                            "product_id": "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_mysql_connectors_connector\\/net:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "MySQL Connectors"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Router Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Router Version 8.4.0-8.4.10",
                                            "product_id": "P-4625V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_router:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Router Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Router Version 9.7.0-9.7.1",
                                            "product_id": "P-4625V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_router:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "MySQL Router"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_InnoDB) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_InnoDB) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: DDL) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: DDL) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: DDL)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: JSON) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: JSON) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Replication) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Replication) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin) Version 8.4.0-8.4.10",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin) Version 8.4.0-8.4.10",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer) Version 9.0.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer) Version 9.0.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.0.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_InnoDB) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_InnoDB) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Configurator) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Configurator) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Configurator)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: DDL) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: DDL) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: DDL)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: GIS) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: GIS) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: GIS)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: JSON) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: JSON) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Replication) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: Replication) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin) Version 9.7.0-9.7.1",
                                        "product": {
                                            "name": "MySQL Server(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin) Version 9.7.0-9.7.1",
                                            "product_id": "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mysql_server:9.7.0-9.7.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "MySQL Server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle MySQL"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle NoSQL Database Version 1.7",
                                        "product": {
                                            "name": "Oracle NoSQL Database Version 1.7",
                                            "product_id": "P-13373V-1.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:nosql_database:1.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle NoSQL Database"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle NoSQL Database"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise CC Common Application Objects Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise CC Common Application Objects Version 9.2",
                                            "product_id": "P-8911V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_cc_common_application_objects:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise CC Common Application Objects"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise CRM Common Objects Version 9.2.23",
                                        "product": {
                                            "name": "PeopleSoft Enterprise CRM Common Objects Version 9.2.23",
                                            "product_id": "P-8904V-9.2.23",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_crm_common_objects:9.2.23:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise CRM Common Objects"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise CS Campus Community Version 9.2.38",
                                        "product": {
                                            "name": "PeopleSoft Enterprise CS Campus Community Version 9.2.38",
                                            "product_id": "P-5183V-9.2.38",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_cs_campus_community:9.2.38:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise CS Campus Community"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise CS Financial Aid Version 9.2.38",
                                        "product": {
                                            "name": "PeopleSoft Enterprise CS Financial Aid Version 9.2.38",
                                            "product_id": "P-5178V-9.2.38",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_cs_financial_aid:9.2.38:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise CS Financial Aid"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise CS Student Financials Version 9.2.38",
                                        "product": {
                                            "name": "PeopleSoft Enterprise CS Student Financials Version 9.2.38",
                                            "product_id": "P-5180V-9.2.38",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_cs_student_financials:9.2.38:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise CS Student Financials"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise CS Student Records Version 9.2.38",
                                        "product": {
                                            "name": "PeopleSoft Enterprise CS Student Records Version 9.2.38",
                                            "product_id": "P-5182V-9.2.38",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_cs_student_records:9.2.38:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise CS Student Records"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Billing Argentina Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Billing Argentina Version 9.1",
                                            "product_id": "P-4975V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_billing_argentina:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Billing Argentina"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Cash Management Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Cash Management Version 9.2",
                                            "product_id": "P-4979V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_cash_management:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Cash Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Common Objects Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Common Objects Version 9.2",
                                            "product_id": "P-8923V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Common Objects"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Common Objects Argentina Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Common Objects Argentina Version 9.1",
                                            "product_id": "P-8930V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_argentina:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Common Objects Argentina"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Common Objects Brazil Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Common Objects Brazil Version 9.1",
                                            "product_id": "P-8936V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects_brazil:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Common Objects Brazil"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Engineering Argentina Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Engineering Argentina Version 9.1",
                                            "product_id": "P-4913V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_engineering_argentina:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Engineering Argentina"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Expenses Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Expenses Version 9.2",
                                            "product_id": "P-4988V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_expenses:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Expenses"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN General Ledger Argentina Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN General Ledger Argentina Version 9.1",
                                            "product_id": "P-4993V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_general_ledger_argentina:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN General Ledger Argentina"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Grants Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Grants Version 9.2",
                                            "product_id": "P-4995V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_grants:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Grants"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Manufacturing Argentina Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Manufacturing Argentina Version 9.1",
                                            "product_id": "P-8828V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_manufacturing_argentina:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Manufacturing Argentina"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Manufacturing Brazil Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Manufacturing Brazil Version 9.1",
                                            "product_id": "P-8867V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_manufacturing_brazil:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Manufacturing Brazil"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Pay/Bill Management Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Pay/Bill Management Version 9.2",
                                            "product_id": "P-5007V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_pay\\/bill_management:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Pay/Bill Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Payables Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Payables Version 9.2",
                                            "product_id": "P-5008V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_payables:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Payables"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Program Management Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Program Management Version 9.2",
                                            "product_id": "P-5012V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_program_management:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Program Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Project Costing Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Project Costing Version 9.2",
                                            "product_id": "P-5013V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_project_costing:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Project Costing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Staffing Front Office Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Staffing Front Office Version 9.2",
                                            "product_id": "P-5026V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_staffing_front_office:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Staffing Front Office"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Staffing Front Office Brazil Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Staffing Front Office Brazil Version 9.1",
                                            "product_id": "P-8880V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_staffing_front_office_brazil:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Staffing Front Office Brazil"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN eSettlements Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN eSettlements Version 9.2",
                                            "product_id": "P-4987V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_esettlements:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN eSettlements"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise HCM Global Payroll Mexico Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise HCM Global Payroll Mexico Version 9.2",
                                            "product_id": "P-5063V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_global_payroll_mexico:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise HCM Global Payroll Mexico"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise HCM Global Payroll Switzerland Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise HCM Global Payroll Switzerland Version 9.2",
                                            "product_id": "P-5068V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_global_payroll_switzerland:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise HCM Global Payroll Switzerland"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
                                            "product_id": "P-5071V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise HCM Human Resources"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise HCM Talent Acquisition Manager Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise HCM Talent Acquisition Manager Version 9.2",
                                            "product_id": "P-5078V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_talent_acquisition_manager:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise HCM Talent Acquisition Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise PeopleTools Version 8.61",
                                        "product": {
                                            "name": "PeopleSoft Enterprise PeopleTools Version 8.61",
                                            "product_id": "P-5085V-8.61",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise PeopleTools Version 8.62",
                                        "product": {
                                            "name": "PeopleSoft Enterprise PeopleTools Version 8.62",
                                            "product_id": "P-5085V-8.62",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise PeopleTools"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise SCM Inventory Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise SCM Inventory Version 9.2",
                                            "product_id": "P-5124V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_scm_inventory:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise SCM Inventory"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise SCM Manufacturing Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise SCM Manufacturing Version 9.2",
                                            "product_id": "P-5126V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_scm_manufacturing:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise SCM Manufacturing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise SCM Mobile Inventory Management Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise SCM Mobile Inventory Management Version 9.2",
                                            "product_id": "P-8890V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_scm_mobile_inventory_management:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise SCM Mobile Inventory Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise SCM Order Management Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise SCM Order Management Version 9.2",
                                            "product_id": "P-5127V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_scm_order_management:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise SCM Order Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise SCM Purchasing Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise SCM Purchasing Version 9.2",
                                            "product_id": "P-5133V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_scm_purchasing:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise SCM Purchasing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise SCM Supplier Contract Management Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise SCM Supplier Contract Management Version 9.2",
                                            "product_id": "P-5137V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_scm_supplier_contract_management:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise SCM Supplier Contract Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise SCM eProcurement Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise SCM eProcurement Version 9.2",
                                            "product_id": "P-5118V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_scm_eprocurement:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise SCM eProcurement"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft In-Memory Project Discovery Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft In-Memory Project Discovery Version 9.2",
                                            "product_id": "P-10681V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_in-memory_project_discovery:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft In-Memory Project Discovery"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle PeopleSoft"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Allocation Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Allocation Version 16.0.3",
                                            "product_id": "P-1786V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_allocation:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Allocation Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Allocation Version 19.0.1",
                                            "product_id": "P-1786V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_allocation:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Allocation"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Bulk Data Integration Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Bulk Data Integration Version 16.0.3",
                                            "product_id": "P-12968V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Bulk Data Integration Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Bulk Data Integration Version 19.0.1",
                                            "product_id": "P-12968V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_bulk_data_integration:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Bulk Data Integration"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Retail EFTLink Version 21.0.0-25.0.0",
                                        "product": {
                                            "name": "Oracle Retail EFTLink Version 21.0.0-25.0.0",
                                            "product_id": "P-11516V-21.0.0-25.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_eftlink:21.0.0-25.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail EFTLink"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Extract Tranform and Load Version 13.2.8",
                                        "product": {
                                            "name": "Oracle Retail Extract Tranform and Load Version 13.2.8",
                                            "product_id": "P-1803V-13.2.8",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_extract_tranform_and_load:13.2.8:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Extract Tranform and Load"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Financial Integration(Oracle Retail Financial Integration_EBS Integration) Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Financial Integration(Oracle Retail Financial Integration_EBS Integration) Version 16.0.3",
                                            "product_id": "P-10722(Oracle Retail Financial Integration_EBS Integration)V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Financial Integration(Oracle Retail Financial Integration_PeopleSoft Integration) Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Financial Integration(Oracle Retail Financial Integration_PeopleSoft Integration) Version 16.0.3",
                                            "product_id": "P-10722(Oracle Retail Financial Integration_PeopleSoft Integration)V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Financial Integration Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Financial Integration Version 16.0.3",
                                            "product_id": "P-10722V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Financial Integration(Oracle Retail Financial Integration_EBS Integration) Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Financial Integration(Oracle Retail Financial Integration_EBS Integration) Version 19.0.1",
                                            "product_id": "P-10722(Oracle Retail Financial Integration_EBS Integration)V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Financial Integration(Oracle Retail Financial Integration_PeopleSoft Integration) Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Financial Integration(Oracle Retail Financial Integration_PeopleSoft Integration) Version 19.0.1",
                                            "product_id": "P-10722(Oracle Retail Financial Integration_PeopleSoft Integration)V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Financial Integration Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Financial Integration Version 19.0.1",
                                            "product_id": "P-10722V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Financial Integration"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Integration Bus Version 14.1.3.2",
                                        "product": {
                                            "name": "Oracle Retail Integration Bus Version 14.1.3.2",
                                            "product_id": "P-1807V-14.1.3.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Integration Bus Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Integration Bus Version 16.0.3",
                                            "product_id": "P-1807V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Integration Bus Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Integration Bus Version 19.0.1",
                                            "product_id": "P-1807V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_integration_bus:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Integration Bus"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Invoice Matching Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Invoice Matching Version 16.0.3",
                                            "product_id": "P-1810V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_invoice_matching:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Invoice Matching Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Invoice Matching Version 19.0.1",
                                            "product_id": "P-1810V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_invoice_matching:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Invoice Matching"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Price Management Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Price Management Version 16.0.3",
                                            "product_id": "P-1824V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_price_management:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Price Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Pricing Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Pricing Version 16.0.3",
                                            "product_id": "P-14111V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_pricing:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Pricing Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Pricing Version 19.0.1",
                                            "product_id": "P-14111V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_pricing:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Pricing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Service Backbone Version 16.0.3",
                                        "product": {
                                            "name": "Oracle Retail Service Backbone Version 16.0.3",
                                            "product_id": "P-10867V-16.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_service_backbone:16.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Service Backbone Version 19.0.1",
                                        "product": {
                                            "name": "Oracle Retail Service Backbone Version 19.0.1",
                                            "product_id": "P-10867V-19.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_service_backbone:19.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Service Backbone"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Xstore Point of Service Version 21.0.3",
                                        "product": {
                                            "name": "Oracle Retail Xstore Point of Service Version 21.0.3",
                                            "product_id": "P-11513V-21.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Retail Xstore Point of Service Version 21.0.5-25.0.1",
                                        "product": {
                                            "name": "Oracle Retail Xstore Point of Service Version 21.0.5-25.0.1",
                                            "product_id": "P-11513V-21.0.5-25.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.5-25.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Xstore Point of Service Version 22.0.3",
                                        "product": {
                                            "name": "Oracle Retail Xstore Point of Service Version 22.0.3",
                                            "product_id": "P-11513V-22.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:22.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Xstore Point of Service Version 23.0.3",
                                        "product": {
                                            "name": "Oracle Retail Xstore Point of Service Version 23.0.3",
                                            "product_id": "P-11513V-23.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:23.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Retail Xstore Point of Service Version 24.0.2",
                                        "product": {
                                            "name": "Oracle Retail Xstore Point of Service Version 24.0.2",
                                            "product_id": "P-11513V-24.0.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:24.0.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Retail Xstore Point of Service"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Retail Applications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle SQL Developer(Oracle SQL Developer_Infrastructure) Version 19.3-24.3",
                                        "product": {
                                            "name": "Oracle SQL Developer(Oracle SQL Developer_Infrastructure) Version 19.3-24.3",
                                            "product_id": "P-1875(Oracle SQL Developer_Infrastructure)V-19.3-24.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sql_developer:19.3-24.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle SQL Developer"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "SQL Developer(SQL Developer_Installation) Version 19.3-24.3",
                                        "product": {
                                            "name": "SQL Developer(SQL Developer_Installation) Version 19.3-24.3",
                                            "product_id": "P-1875(SQL Developer_Installation)V-19.3-24.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sql_developer:19.3-24.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "SQL Developer(SQL Developer_Installation) Version 22.4.0",
                                        "product": {
                                            "name": "SQL Developer(SQL Developer_Installation) Version 22.4.0",
                                            "product_id": "P-1875(SQL Developer_Installation)V-22.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sql_developer:22.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "SQL Developer(SQL Developer_Installation) Version 23.1",
                                        "product": {
                                            "name": "SQL Developer(SQL Developer_Installation) Version 23.1",
                                            "product_id": "P-1875(SQL Developer_Installation)V-23.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sql_developer:23.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "SQL Developer(SQL Developer_Installation) Version 24.2",
                                        "product": {
                                            "name": "SQL Developer(SQL Developer_Installation) Version 24.2",
                                            "product_id": "P-1875(SQL Developer_Installation)V-24.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sql_developer:24.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "SQL Developer(SQL Developer_Installation) Version 24.2.0",
                                        "product": {
                                            "name": "SQL Developer(SQL Developer_Installation) Version 24.2.0",
                                            "product_id": "P-1875(SQL Developer_Installation)V-24.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sql_developer:24.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "SQL Developer(SQL Developer_Installation) Version 24.3",
                                        "product": {
                                            "name": "SQL Developer(SQL Developer_Installation) Version 24.3",
                                            "product_id": "P-1875(SQL Developer_Installation)V-24.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sql_developer:24.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "SQL Developer"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle SQL Developer"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel Apps - Marketing Version 17.0-26.5",
                                        "product": {
                                            "name": "Siebel Apps - Marketing Version 17.0-26.5",
                                            "product_id": "P-8974V-17.0-26.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_apps_-_marketing:17.0-26.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel Apps - Marketing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Administration Version 17.0-26.5",
                                        "product": {
                                            "name": "Siebel CRM Administration Version 17.0-26.5",
                                            "product_id": "P-9747V-17.0-26.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_administration:17.0-26.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Administration"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Cloud Applications Version 22.3-26.4",
                                        "product": {
                                            "name": "Siebel CRM Cloud Applications Version 22.3-26.4",
                                            "product_id": "P-14107V-22.3-26.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_cloud_applications:22.3-26.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Cloud Applications Version 22.3-26.5",
                                        "product": {
                                            "name": "Siebel CRM Cloud Applications Version 22.3-26.5",
                                            "product_id": "P-14107V-22.3-26.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_cloud_applications:22.3-26.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Cloud Applications"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Deployment Version 17.0-26.4",
                                        "product": {
                                            "name": "Siebel CRM Deployment Version 17.0-26.4",
                                            "product_id": "P-9019V-17.0-26.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:17.0-26.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Deployment Version 17.0-26.5",
                                        "product": {
                                            "name": "Siebel CRM Deployment Version 17.0-26.5",
                                            "product_id": "P-9019V-17.0-26.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:17.0-26.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Deployment"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Development Version 17.0-26.3",
                                        "product": {
                                            "name": "Siebel CRM Development Version 17.0-26.3",
                                            "product_id": "P-9001V-17.0-26.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_development:17.0-26.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Development Version 17.0-26.5",
                                        "product": {
                                            "name": "Siebel CRM Development Version 17.0-26.5",
                                            "product_id": "P-9001V-17.0-26.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_development:17.0-26.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Development"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM End User Version 17.0-26.5",
                                        "product": {
                                            "name": "Siebel CRM End User Version 17.0-26.5",
                                            "product_id": "P-9011V-17.0-26.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_end_user:17.0-26.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM End User Version 24.4-26.3",
                                        "product": {
                                            "name": "Siebel CRM End User Version 24.4-26.3",
                                            "product_id": "P-9011V-24.4-26.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_end_user:24.4-26.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM End User"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Integration Version 17.0-26.4",
                                        "product": {
                                            "name": "Siebel CRM Integration Version 17.0-26.4",
                                            "product_id": "P-9008V-17.0-26.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_integration:17.0-26.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Integration Version 17.0-26.5",
                                        "product": {
                                            "name": "Siebel CRM Integration Version 17.0-26.5",
                                            "product_id": "P-9008V-17.0-26.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_integration:17.0-26.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Siebel CRM Integration Version 25.12-26.5",
                                        "product": {
                                            "name": "Siebel CRM Integration Version 25.12-26.5",
                                            "product_id": "P-9008V-25.12-26.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_integration:25.12-26.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Integration"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Siebel CRM"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Spatial Studio Version 23.2.1",
                                        "product": {
                                            "name": "Oracle Spatial Studio Version 23.2.1",
                                            "product_id": "P-13600V-23.2.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:spatial_studio:23.2.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Spatial Studio Version 24.2",
                                        "product": {
                                            "name": "Oracle Spatial Studio Version 24.2",
                                            "product_id": "P-13600V-24.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:spatial_studio:24.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Spatial Studio"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Spatial Studio"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Agile Engineering Data Management Version 6.2.1",
                                        "product": {
                                            "name": "Oracle Agile Engineering Data Management Version 6.2.1",
                                            "product_id": "P-4436V-6.2.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Agile Engineering Data Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Agile PLM Version 9.3.6",
                                        "product": {
                                            "name": "Oracle Agile PLM Version 9.3.6",
                                            "product_id": "P-4461V-9.3.6",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Agile PLM"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Agile PLM MCAD Connector Version 3.6",
                                        "product": {
                                            "name": "Oracle Agile PLM MCAD Connector Version 3.6",
                                            "product_id": "P-4440V-3.6",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Agile PLM MCAD Connector"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Agile Product Lifecycle Management for Process Version 6.2.4",
                                        "product": {
                                            "name": "Oracle Agile Product Lifecycle Management for Process Version 6.2.4",
                                            "product_id": "P-4445V-6.2.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Agile Product Lifecycle Management for Process"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Demantra Demand Management Version 12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Demantra Demand Management Version 12.2.3-12.2.15",
                                            "product_id": "P-2100V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:demantra_demand_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Demantra Demand Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Product Lifecycle Analytics Version 3.6.1",
                                        "product": {
                                            "name": "Oracle Product Lifecycle Analytics Version 3.6.1",
                                            "product_id": "P-9387V-3.6.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Product Lifecycle Analytics"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Transportation Management Version 6.5.3",
                                        "product": {
                                            "name": "Oracle Transportation Management Version 6.5.3",
                                            "product_id": "P-1991V-6.5.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:transportation_management:6.5.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Transportation Management"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Supply Chain"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Solaris Version 11.3",
                                        "product": {
                                            "name": "Oracle Solaris Version 11.3",
                                            "product_id": "P-10006V-11.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:solaris:11.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Solaris Version 11.4",
                                        "product": {
                                            "name": "Oracle Solaris Version 11.4",
                                            "product_id": "P-10006V-11.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:solaris:11.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Solaris"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Systems"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "TimesTen In-Memory Database Version 22.1.1.1.0",
                                        "product": {
                                            "name": "TimesTen In-Memory Database Version 22.1.1.1.0",
                                            "product_id": "P-1870V-22.1.1.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:22.1.1.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "TimesTen In-Memory Database Version 26.1.1.1.0",
                                        "product": {
                                            "name": "TimesTen In-Memory Database Version 26.1.1.1.0",
                                            "product_id": "P-1870V-26.1.1.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "TimesTen In-Memory Database"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle TimesTen In-Memory Database"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 25.10",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 25.10",
                                            "product_id": "P-2245V-25.10",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:25.10:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 25.4",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 25.4",
                                            "product_id": "P-2245V-25.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:25.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 26.4",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 26.4",
                                            "product_id": "P-2245V-26.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:26.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Application Framework Version 4.3.0.5.0-4.3.0.6.0",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.3.0.5.0-4.3.0.6.0",
                                            "product_id": "P-2245V-4.3.0.5.0-4.3.0.6.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.3.0.5.0-4.3.0.6.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
                                            "product_id": "P-2245V-4.3.0.6.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.3.0.6.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
                                            "product_id": "P-2245V-4.4.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Application Framework Version 4.4.0.2.0-4.4.0.4.0",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.4.0.2.0-4.4.0.4.0",
                                            "product_id": "P-2245V-4.4.0.2.0-4.4.0.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.2.0-4.4.0.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
                                            "product_id": "P-2245V-4.5.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Application Framework Version 4.5.0.0.0-4.5.0.1.1",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.5.0.0.0-4.5.0.1.1",
                                            "product_id": "P-2245V-4.5.0.0.0-4.5.0.1.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.0.0-4.5.0.1.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 4.5.0.1.1",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.5.0.1.1",
                                            "product_id": "P-2245V-4.5.0.1.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 4.5.0.1.3",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.5.0.1.3",
                                            "product_id": "P-2245V-4.5.0.1.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Application Framework Version 4.5.0.2.0",
                                        "product": {
                                            "name": "Oracle Utilities Application Framework Version 4.5.0.2.0",
                                            "product_id": "P-2245V-4.5.0.2.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.2.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Utilities Application Framework"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 2.4.0.1.0-2.4.0.1.32",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.4.0.1.0-2.4.0.1.32",
                                            "product_id": "P-2241V-2.4.0.1.0-2.4.0.1.32",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.4.0.1.0-2.4.0.1.32:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 2.5.0.1.0-2.5.0.1.17",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.5.0.1.0-2.5.0.1.17",
                                            "product_id": "P-2241V-2.5.0.1.0-2.5.0.1.17",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.1.0-2.5.0.1.17:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 2.5.0.2.0-2.5.0.2.11",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.5.0.2.0-2.5.0.2.11",
                                            "product_id": "P-2241V-2.5.0.2.0-2.5.0.2.11",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.2.0-2.5.0.2.11:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 2.6.0.1.0-2.6.0.1.11",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.6.0.1.0-2.6.0.1.11",
                                            "product_id": "P-2241V-2.6.0.1.0-2.6.0.1.11",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.1.0-2.6.0.1.11:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 2.6.0.1.0-2.6.0.1.12",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.6.0.1.0-2.6.0.1.12",
                                            "product_id": "P-2241V-2.6.0.1.0-2.6.0.1.12",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.1.0-2.6.0.1.12:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 2.6.0.2.0-2.6.0.2.7",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.6.0.2.0-2.6.0.2.7",
                                            "product_id": "P-2241V-2.6.0.2.0-2.6.0.2.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.2.0-2.6.0.2.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 2.6.0.2.0-2.6.0.2.8",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.6.0.2.0-2.6.0.2.8",
                                            "product_id": "P-2241V-2.6.0.2.0-2.6.0.2.8",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.2.0-2.6.0.2.8:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Network Management System Version 25.12.0.0.0",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 25.12.0.0.0",
                                            "product_id": "P-2241V-25.12.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:25.12.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 25.12.0.0.0-25.12.0.0.1",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 25.12.0.0.0-25.12.0.0.1",
                                            "product_id": "P-2241V-25.12.0.0.0-25.12.0.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:25.12.0.0.0-25.12.0.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "Oracle Utilities Network Management System Version 25.12.0.0.0-25.12.0.0.2",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 25.12.0.0.0-25.12.0.0.2",
                                            "product_id": "P-2241V-25.12.0.0.0-25.12.0.0.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:25.12.0.0.0-25.12.0.0.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Utilities Network Management System"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Testing Accelerator Version 25.4.0.0.3",
                                        "product": {
                                            "name": "Oracle Utilities Testing Accelerator Version 25.4.0.0.3",
                                            "product_id": "P-13784V-25.4.0.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_testing_accelerator:25.4.0.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Testing Accelerator Version 7.0.0.0.8",
                                        "product": {
                                            "name": "Oracle Utilities Testing Accelerator Version 7.0.0.0.8",
                                            "product_id": "P-13784V-7.0.0.0.8",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_testing_accelerator:7.0.0.0.8:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Utilities Testing Accelerator Version 7.0.0.1.7",
                                        "product": {
                                            "name": "Oracle Utilities Testing Accelerator Version 7.0.0.1.7",
                                            "product_id": "P-13784V-7.0.0.1.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_testing_accelerator:7.0.0.1.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Utilities Testing Accelerator"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Utilities Applications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle VM VirtualBox Version 7.2.12",
                                        "product": {
                                            "name": "Oracle VM VirtualBox Version 7.2.12",
                                            "product_id": "P-8370V-7.2.12",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle VM VirtualBox Version 7.2.8",
                                        "product": {
                                            "name": "Oracle VM VirtualBox Version 7.2.8",
                                            "product_id": "P-8370V-7.2.8",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:vm_virtualbox:7.2.8:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle VM VirtualBox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Virtualization"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2014-3643",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager for Fusion Middleware",
                    "text": "39106493"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Web Services Management (Eclipse Jersey)).   The supported version that is affected is 13.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager for Fusion Middleware.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Fusion Middleware accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1369(Oracle Enterprise Manager for Fusion Middleware_Web Services Management)V-13.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1369(Oracle Enterprise Manager for Fusion Middleware_Web Services Management)V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1369(Oracle Enterprise Manager for Fusion Middleware_Web Services Management)V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2019-14892",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39490394"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework (jackson-databind)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ]
        },
        {
            "cve": "CVE-2019-20330",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39490394"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework (jackson-databind)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ]
        },
        {
            "cve": "CVE-2020-8840",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39490394"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework (jackson-databind)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ]
        },
        {
            "cve": "CVE-2020-8908",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39440144"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Google Guava)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2020-9547",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39490394"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework (jackson-databind)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2021-22555",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne General Ledger",
                    "text": "39294816"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation (swift)).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne General Ledger executes to compromise JD Edwards EnterpriseOne General Ledger.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne General Ledger. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4737V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4737V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4737V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2021-28170",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39439230"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Jakarta Expression Language)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2021-3283",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39067048"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Traefik)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2021-3629",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0-15.2.0.0.0"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39517009"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Elastic Charging Engine (Undertow)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-9742V-15.0.0.0.0-15.0.1.0.0",
                    "P-9742V-15.1.0.0.0-15.2.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9742V-15.0.0.0.0-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0-15.2.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0-15.2.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2022-1941",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2022-25315",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340139"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management (LibExpat)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2022-28948",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39020243"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (OpenTelemetry-Go)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2022-3171",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0",
                    "P-9019V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2023-29053",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "inline_mitigations_already_exist",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39286779"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Libraries (JTOpen)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2023-30796",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "inline_mitigations_already_exist",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39286779"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Libraries (JTOpen)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2023-34453",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2023-34454",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2023-34455",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2023-35116",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39490623"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (jackson-databind)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.5"
                ],
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2023-39410",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39018802"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (WebAssembly Micro Runtime)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2023-40577",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39057050"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Alertmanager)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as  unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2023-43642",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2023-5981",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687789"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (glibc)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Certificate Management executes to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2024-0406",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2024-0553",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687789"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (glibc)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Certificate Management executes to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2024-21117",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527408"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ]
        },
        {
            "cve": "CVE-2024-21118",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527408"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ]
        },
        {
            "cve": "CVE-2024-21119",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527408"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ]
        },
        {
            "cve": "CVE-2024-21120",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527408"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ]
        },
        {
            "cve": "CVE-2024-24557",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2024-24824",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2024-27532",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39018802"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (WebAssembly Micro Runtime)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2024-28168",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "37570725"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Healthcheck (Apache FOP)).   The supported version that is affected is 25.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Autonomous Health Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14634V-25.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-25.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14634V-25.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2024-29018",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2024-29371",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39439503"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (jose4j)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2024-36129",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2024-36623",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2024-37996",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "inline_mitigations_already_exist",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39286779"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Libraries (JTOpen)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2024-37997",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "inline_mitigations_already_exist",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39286779"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Libraries (JTOpen)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2024-38820",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39328995"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-12.2.1.4.0",
                    "P-4647V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0",
                        "P-4647V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ]
        },
        {
            "cve": "CVE-2024-39908",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39057061"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (REXML)).  Supported versions that are affected are 22.3-26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2024-40635",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39020243"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (OpenTelemetry-Go)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2024-45801",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38872184"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface (DOMPurify)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM End User accessible data as well as  unauthorized read access to a subset of Siebel CRM End User accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2024-47554",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SQL Developer",
                    "text": "38546309"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39490643"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle SQL Developer (component: Infrastructure (Apache Commons VFS)).  Supported versions that are affected are 19.3-24.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SQL Developer accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Commons IO)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1875(Oracle SQL Developer_Infrastructure)V-19.3-24.3"
                ],
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15",
                        "P-1875(Oracle SQL Developer_Infrastructure)V-19.3-24.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2024-47561",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39478958"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39018802"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (WebAssembly Micro Runtime)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Common Core (Apache Avro)).  Supported versions that are affected are 14.6.0-14.8.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13487V-14.6.0-14.8.0",
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13487V-14.6.0-14.8.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2024-47875",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38872184"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface (DOMPurify)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM End User accessible data as well as  unauthorized read access to a subset of Siebel CRM End User accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2024-48910",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38872184"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface (DOMPurify)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM End User accessible data as well as  unauthorized read access to a subset of Siebel CRM End User accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2024-52046",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39354724"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Mina)).   The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ]
        },
        {
            "cve": "CVE-2024-56128",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of SQL Developer",
                    "text": "39276891"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the SQL Developer product of Oracle SQL Developer (component: Installation (Apache Kafka)).  Supported versions that are affected are 19.3-24.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all SQL Developer accessible data as well as  unauthorized access to critical data or complete access to all SQL Developer accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1875(SQL Developer_Installation)V-19.3-24.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1875(SQL Developer_Installation)V-19.3-24.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2024-6763",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2024-7254",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39235731"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Google Protobuf-Java)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0",
                    "P-9019V-17.0-26.5"
                ],
                "known_not_affected": [
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-0509",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of SQL Developer",
                    "text": "37795488"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the SQL Developer product of Oracle SQL Developer (component: Installation).   The supported version that is affected is 24.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of SQL Developer accessible data as well as  unauthorized read access to a subset of SQL Developer accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1875(SQL Developer_Installation)V-24.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1875(SQL Developer_Installation)V-24.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2025-11143",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39058558"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
                    "text": "39059478"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Eclipse Jetty)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Third Party (Eclipse Jetty)).   The supported version that is affected is 26.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Cloud Native Session Border Controller accessible data as well as  unauthorized access to critical data or complete access to all Oracle Cloud Native Session Border Controller accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14762V-26.0.0",
                    "P-4647V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14762V-26.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU269"
                }
            ]
        },
        {
            "cve": "CVE-2025-11953",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38990566"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (React)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2025-12183",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2025-1220",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39123912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (PHP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-12383",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "38955906"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST (Eclipse Jersey)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-17.0-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-12543",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0-15.2.0.0.0"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39517009"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Elastic Charging Engine (Undertow)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-9742V-15.0.0.0.0-15.0.1.0.0",
                    "P-9742V-15.1.0.0.0-15.2.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9742V-15.0.0.0.0-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0-15.2.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0-15.2.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-13034",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "38858214"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "38858209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge (curl)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search Platform Services executes to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (curl)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                }
            ]
        },
        {
            "cve": "CVE-2025-13151",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "38850306"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "38850318"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Libtasn1)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Libtasn1)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-14547V-25.1.200",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-14547V-24.3.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14974V-25.2.200",
                        "P-14547V-24.2.0",
                        "P-14974V-25.1.200",
                        "P-14547V-24.3.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-13465",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39698092"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39698031"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Embedded Web UI for Services (Axios)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Embedded Web UI for Services (Lodash)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-13837",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39001631"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Python)).  Supported versions that are affected are 22.3-26.4. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-14017",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "38858214"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "38858209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge (curl)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search Platform Services executes to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (curl)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0",
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-14087",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
                    "text": "39618735"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (glib)).  Supported versions that are affected are 25.1.203 and  25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Console accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14250V-25.1.203",
                    "P-14250V-25.2.201"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14250V-25.2.201",
                        "P-14250V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU246"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14250V-25.2.201",
                        "P-14250V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-14177",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39123912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (PHP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-14178",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39123912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (PHP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-14180",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39123912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (PHP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-14524",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "38858214"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "38858209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge (curl)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search Platform Services executes to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (curl)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                }
            ]
        },
        {
            "cve": "CVE-2025-14819",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "38858214"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "38858209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge (curl)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search Platform Services executes to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (curl)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                }
            ]
        },
        {
            "cve": "CVE-2025-14821",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464356"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39464357"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464359"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464360"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464361"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464362"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Slice Selection Function executes to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (libssh)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14277V-25.2.200",
                    "P-14117V-25.2.200",
                    "P-14117V-25.1.200",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14122V-24.2.5",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14121V-25.2.200",
                        "P-14117V-25.2.100",
                        "P-14277V-25.2.200",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200",
                        "P-14130V-25.2.200"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-15079",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "38858214"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "38858209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge (curl)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search Platform Services executes to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (curl)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                }
            ]
        },
        {
            "cve": "CVE-2025-15224",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "38858214"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "38858209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge (curl)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search Platform Services executes to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (curl)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                }
            ]
        },
        {
            "cve": "CVE-2025-15599",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39114090"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (DOMPurify)).  Supported versions that are affected are 4.3.0.5.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0-4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Application Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Application Framework accessible data as well as  unauthorized read access to a subset of Oracle Utilities Application Framework accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2245V-4.3.0.5.0-4.3.0.6.0",
                    "P-2245V-4.5.0.0.0-4.5.0.1.1",
                    "P-2245V-4.5.0.1.3",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-2245V-4.5.0.2.0",
                    "P-2245V-25.4",
                    "P-2245V-26.4",
                    "P-2245V-25.10",
                    "P-2245V-4.4.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.3.0.5.0-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0-4.5.0.1.1",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-25.4",
                        "P-2245V-26.4",
                        "P-2245V-25.10",
                        "P-2245V-4.4.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2025-1735",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39123912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (PHP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-21502",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of SQL Developer",
                    "text": "37795488"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the SQL Developer product of Oracle SQL Developer (component: Installation).   The supported version that is affected is 24.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of SQL Developer accessible data as well as  unauthorized read access to a subset of SQL Developer accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1875(SQL Developer_Installation)V-24.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1875(SQL Developer_Installation)V-24.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1875(SQL Developer_Installation)V-24.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-26791",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38872184"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface (DOMPurify)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM End User accessible data as well as  unauthorized read access to a subset of Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-17.0-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-27553",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SQL Developer",
                    "text": "38546309"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle SQL Developer (component: Infrastructure (Apache Commons VFS)).  Supported versions that are affected are 19.3-24.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SQL Developer accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1875(Oracle SQL Developer_Infrastructure)V-19.3-24.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1875(Oracle SQL Developer_Infrastructure)V-19.3-24.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1875(Oracle SQL Developer_Infrastructure)V-19.3-24.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-27817",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of SQL Developer",
                    "text": "39276891"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the SQL Developer product of Oracle SQL Developer (component: Installation (Apache Kafka)).  Supported versions that are affected are 19.3-24.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all SQL Developer accessible data as well as  unauthorized access to critical data or complete access to all SQL Developer accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1875(SQL Developer_Installation)V-19.3-24.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1875(SQL Developer_Installation)V-19.3-24.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2025-27821",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle NoSQL Database",
                    "text": "39022624"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39440309"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle NoSQL Database (component: Administration (Apache Hadoop)).   The supported version that is affected is 1.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle NoSQL Database.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle NoSQL Database accessible data as well as  unauthorized read access to a subset of Oracle NoSQL Database accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle NoSQL Database. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Hadoop)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13373V-1.7"
                ],
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13373V-1.7",
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13373V-1.7"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-29088",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38990566"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (React)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2025-30153",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-30204",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39020243"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (OpenTelemetry-Go)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-31651",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "38003382"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Apache Tomcat)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-32988",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "38206348"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (GnuTLS)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function as well as  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                }
            ]
        },
        {
            "cve": "CVE-2025-32989",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "38206348"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (GnuTLS)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function as well as  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                }
            ]
        },
        {
            "cve": "CVE-2025-32990",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "38206348"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (GnuTLS)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function as well as  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14130V-25.2.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-33042",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
                    "text": "38993732"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Origination",
                    "text": "38993733"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "38993727"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39018802"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
                    "text": "38993752"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache Avro)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Corporate Lending Process Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Corporate Lending Process Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Apache Avro)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Liquidity Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration (Apache Avro)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as  unauthorized read access to a subset of Oracle Banking Origination accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Relationship Management (Apache Avro)).  Supported versions that are affected are 5.0.0.0-5.0.9.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Healthcare Master Person Index accessible data as well as  unauthorized read access to a subset of Oracle Healthcare Master Person Index accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Healthcare Master Person Index. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (WebAssembly Micro Runtime)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8575V-5.0.0.0-5.0.9.6",
                    "P-13304V-14.5.0-14.8.0",
                    "P-13701V-14.6.0-14.8.0",
                    "P-14325V-14.5.0-14.8.0",
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13304V-14.5.0-14.8.0",
                        "P-13701V-14.6.0-14.8.0",
                        "P-14325V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8575V-5.0.0.0-5.0.9.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU271"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8575V-5.0.0.0-5.0.9.6",
                        "P-13304V-14.5.0-14.8.0",
                        "P-13701V-14.6.0-14.8.0",
                        "P-14325V-14.5.0-14.8.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-3445",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-37731",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-41248",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Payments",
                    "text": "38517097"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Payments Core (Spring Security)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Payments accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13011V-14.5.0-14.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13011V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13011V-14.5.0-14.8.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-41249",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
                    "text": "38517470"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Spring Framework)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13304V-14.6.0-14.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13304V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13304V-14.6.0-14.8.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-4877",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38263965"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (libssh)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0-10.0.15. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.1.0-10.0.15",
                    "P-10899V-9.0.0",
                    "P-10899V-9.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0-10.0.15",
                        "P-10899V-9.0.0",
                        "P-10899V-9.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                }
            ]
        },
        {
            "cve": "CVE-2025-4878",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38263965"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (libssh)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0-10.0.15. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.1.0-10.0.15",
                    "P-10899V-9.0.0",
                    "P-10899V-9.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0-10.0.15",
                        "P-10899V-9.0.0",
                        "P-10899V-9.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                }
            ]
        },
        {
            "cve": "CVE-2025-48924",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-10945V-23.8.0-23.26.1",
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Allocation",
                    "text": "38420988"
                },
                {
                    "system_name": "Oracle Bug ID of SQL Developer",
                    "text": "38421182"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Invoice Matching",
                    "text": "38421006"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39140969"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39439896"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Pricing",
                    "text": "38421014"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
                    "text": "39559431"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
                    "text": "39237434"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Allocation product of Oracle Retail Applications (component: Security (Apache Commons Lang)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Allocation.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Allocation. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Invoice Matching product of Oracle Retail Applications (component: Security (Apache Commons Lang)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Invoice Matching.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Invoice Matching. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Pricing product of Oracle Retail Applications (component: Pricing - Security (Apache Commons Lang)).  Supported versions that are affected are 19.0.1 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Pricing.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Pricing. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the SQL Developer product of Oracle SQL Developer (component: Installation (Apache Commons Lang)).  Supported versions that are affected are 22.4.0, 23.1, 24.2, 24.2.0 and  24.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise SQL Developer.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of SQL Developer. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Commons Lang)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: OGG Orchestration Service (Apache Commons Lang)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Commons Lang)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Fusion Middleware (component: Oracle Database Client for Fusion Middleware (Apache Commons Lang)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Fusion Middleware executes to compromise Oracle Fusion Middleware.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Fusion Middleware. CVSS 3.1 Base Score 3.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1875(SQL Developer_Installation)V-22.4.0",
                    "P-4647V-14.1.2.0.0",
                    "P-1786V-16.0.3",
                    "P-1786V-19.0.1",
                    "P-14111V-19.0.1",
                    "P-1875(SQL Developer_Installation)V-23.1",
                    "P-1810V-16.0.3",
                    "P-1875(SQL Developer_Installation)V-24.2",
                    "P-1810V-19.0.1",
                    "P-1875(SQL Developer_Installation)V-24.3",
                    "P-14111V-16.0.3",
                    "P-1032V-14.1.2.0.0",
                    "P-1875(SQL Developer_Installation)V-24.2.0"
                ],
                "known_not_affected": [
                    "P-10945V-23.8.0-23.26.1",
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1810V-19.0.1",
                        "P-1786V-16.0.3",
                        "P-1786V-19.0.1",
                        "P-14111V-16.0.3",
                        "P-14111V-19.0.1",
                        "P-1810V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1875(SQL Developer_Installation)V-22.4.0",
                        "P-1875(SQL Developer_Installation)V-24.3",
                        "P-10945V-23.8.0-23.26.1",
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15",
                        "P-1875(SQL Developer_Installation)V-23.1",
                        "P-1875(SQL Developer_Installation)V-24.2.0",
                        "P-1875(SQL Developer_Installation)V-24.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0",
                        "P-1032V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1810V-19.0.1",
                        "P-1875(SQL Developer_Installation)V-22.4.0",
                        "P-1875(SQL Developer_Installation)V-24.3",
                        "P-1786V-16.0.3",
                        "P-1786V-19.0.1",
                        "P-14111V-16.0.3",
                        "P-14111V-19.0.1",
                        "P-1875(SQL Developer_Installation)V-23.1",
                        "P-1810V-16.0.3",
                        "P-1875(SQL Developer_Installation)V-24.2.0",
                        "P-1875(SQL Developer_Installation)V-24.2"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10945V-23.8.0-23.26.1"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 3.3,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1032V-14.1.2.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-10945V-23.8.0-23.26.1",
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-48976",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "38189922"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Experience Manager (Apache Commons FileUpload)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-5115",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39439076"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Eclipse Jetty)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-5222",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39091784"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (ICU)).  Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-5318",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38263965"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (libssh)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0-10.0.15. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.1.0-10.0.15",
                    "P-10899V-9.0.0",
                    "P-10899V-9.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0-10.0.15",
                        "P-10899V-9.0.0",
                        "P-10899V-9.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10899V-9.1.0-10.0.15",
                        "P-10899V-9.0.0",
                        "P-10899V-9.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-5351",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38263965"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (libssh)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0-10.0.15. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.1.0-10.0.15",
                    "P-10899V-9.0.0",
                    "P-10899V-9.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0-10.0.15",
                        "P-10899V-9.0.0",
                        "P-10899V-9.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                }
            ]
        },
        {
            "cve": "CVE-2025-5372",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38263965"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (libssh)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0-10.0.15. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.1.0-10.0.15",
                    "P-10899V-9.0.0",
                    "P-10899V-9.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0-10.0.15",
                        "P-10899V-9.0.0",
                        "P-10899V-9.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                }
            ]
        },
        {
            "cve": "CVE-2025-5449",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38263965"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (libssh)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0-10.0.15. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.1.0-10.0.15",
                    "P-10899V-9.0.0",
                    "P-10899V-9.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0-10.0.15",
                        "P-10899V-9.0.0",
                        "P-10899V-9.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                }
            ]
        },
        {
            "cve": "CVE-2025-54920",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39319678"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Third Party (Apache Spark)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.15. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of GoldenGate Stream Analytics as well as  unauthorized update, insert or delete access to some of GoldenGate Stream Analytics accessible data and  unauthorized read access to a subset of GoldenGate Stream Analytics accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-55130",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38875877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ]
        },
        {
            "cve": "CVE-2025-55131",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38875877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ]
        },
        {
            "cve": "CVE-2025-55132",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38875877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ]
        },
        {
            "cve": "CVE-2025-58050",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39105072"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "39105101"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (PCRE2)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Third Party (PCRE2)).  Supported versions that are affected are 2.6.0.1.0-2.6.0.1.11 and  2.6.0.2.0-2.6.0.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Network Management System. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2241V-2.6.0.1.0-2.6.0.1.11",
                    "P-2241V-2.6.0.2.0-2.6.0.2.7"
                ],
                "known_not_affected": [
                    "P-14122V-24.2.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-2.6.0.1.0-2.6.0.1.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2241V-2.6.0.1.0-2.6.0.1.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.7"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-58057",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2025-58767",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38990566"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (React)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2025-59250",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Administration",
                    "text": "38952495"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival (JDBC Driver for SQL Server)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via SQL to compromise Siebel CRM Administration.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Administration accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Administration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9747V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9747V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9747V-17.0-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-59465",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38875877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-59466",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38875877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ]
        },
        {
            "cve": "CVE-2025-5987",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38263965"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (libssh)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0-10.0.15. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.1.0-10.0.15",
                    "P-10899V-9.0.0",
                    "P-10899V-9.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0-10.0.15",
                        "P-10899V-9.0.0",
                        "P-10899V-9.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                }
            ]
        },
        {
            "cve": "CVE-2025-62725",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39020243"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (OpenTelemetry-Go)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2025-6395",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "38206348"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (GnuTLS)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function as well as  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                }
            ]
        },
        {
            "cve": "CVE-2025-64713",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39018802"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (WebAssembly Micro Runtime)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-6491",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39123912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (PHP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-66021",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38961710"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (Java HTML Sanitizer)).   The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-66418",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "38740313"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38740319"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "38740314"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Origination",
                    "text": "39145768"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (urllib3)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (urllib3)).   The supported version that is affected is 24.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: ATS Framework (urllib3)).  Supported versions that are affected are 9.0.0.0.0, 9.0.1.0.0 and  9.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration (urllib3)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14325V-14.6.0-14.8.0",
                    "P-10899V-9.0.0.0.0",
                    "P-10899V-9.1.0.0.0",
                    "P-14130V-25.2.200",
                    "P-10899V-9.0.1.0.0",
                    "P-14277V-24.2.7"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-24.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0.0.0",
                        "P-10899V-9.0.0.0.0",
                        "P-10899V-9.0.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14325V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10899V-9.1.0.0.0",
                        "P-14277V-24.2.7",
                        "P-10899V-9.0.0.0.0",
                        "P-14130V-25.2.200",
                        "P-10899V-9.0.1.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-66471",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "38740313"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "38740319"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "38740314"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (urllib3)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (urllib3)).   The supported version that is affected is 24.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: ATS Framework (urllib3)).  Supported versions that are affected are 9.0.0.0.0, 9.0.1.0.0 and  9.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.0.0.0.0",
                    "P-10899V-9.1.0.0.0",
                    "P-14130V-25.2.200",
                    "P-10899V-9.0.1.0.0",
                    "P-14277V-24.2.7"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-24.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0.0.0",
                        "P-10899V-9.0.0.0.0",
                        "P-10899V-9.0.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-66566",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of SQL Developer",
                    "text": "38776256"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the SQL Developer product of Oracle SQL Developer (component: Installation (lz4-java)).  Supported versions that are affected are 19.3-24.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all SQL Developer accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.5",
                    "P-1875(SQL Developer_Installation)V-19.3-24.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1875(SQL Developer_Installation)V-19.3-24.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1875(SQL Developer_Installation)V-19.3-24.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-66614",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39226171"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2025-67030",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39140969"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39204900"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39439948"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39482881"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Commons Lang)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration (Plexus Utils)).  Supported versions that are affected are 25.12-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Plexus Utils)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Maven Shared Utils)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of GoldenGate Stream Analytics accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-25.12-26.5",
                    "P-4647V-14.1.2.0.0",
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                ],
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-25.12-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15",
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-25.12-26.5",
                        "P-4647V-14.1.2.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 1.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-67721",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39440118"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39235724"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39432971"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39128758"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration (Aircompressor)).  Supported versions that are affected are 25.12-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Aircompressor)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Third Party (Aircompressor)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all GoldenGate Stream Analytics accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Aircompressor)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 2.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-25.12-26.5",
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                ],
                "known_not_affected": [
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-25.12-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20",
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-25.12-26.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 2.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-67735",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Veridata",
                    "text": "39119198"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Veridata product of Oracle GoldenGate (component: Thirdparty Jars (Netty)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11705V-23.2",
                    "P-13487V-14.5.0-14.8.0",
                    "P-11705V-23.1"
                ],
                "known_not_affected": [
                    "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-68161",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39399100"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39399068"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Spatial Studio",
                    "text": "39398854"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Price Management",
                    "text": "39399108"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39398930"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
                    "text": "39398851"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39398935"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39398934"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39398932"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39198313"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39398938"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39398937"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39621889"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39499467"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Extract Tranform and Load",
                    "text": "39399096"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399097"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
                    "text": "39742428"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39399132"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39398924"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39398928"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39398927"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39398926"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
                    "text": "39399048"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Bulk Data Integration",
                    "text": "39399086"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39399043"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39399121"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39398953"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39398997"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39398952"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39398950"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
                    "text": "39399049"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Gateway",
                    "text": "39399127"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39213017"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39360371"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39398958"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "38797512"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager for MySQL Database",
                    "text": "38857230"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39212120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail EFTLink",
                    "text": "39399094"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483308"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
                    "text": "39399051"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39399111"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39399114"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39398864"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39298054"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39398863"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
                    "text": "39398944"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39398988"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Instant Messaging Server",
                    "text": "39398943"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
                    "text": "39398949"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM MCAD Connector",
                    "text": "38797524"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39278469"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Essbase",
                    "text": "38797647"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Log4j)).   The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client (Apache Log4j)).   The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Agile PLM MCAD Connector.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Essbase (component: Essbase Web Platform (Apache Log4j)).   The supported version that is affected is 21.8.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Essbase accessible data as well as  unauthorized read access to a subset of Oracle Essbase accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager for MySQL Database product of Oracle Enterprise Manager (component: EM Plugin: General (Apache Log4j)).  Supported versions that are affected are 13.5.4.0.0-13.5.5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager for MySQL Database.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager for MySQL Database accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager for MySQL Database accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Log4j)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Log4j)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Log4j)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Log4j)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Application Framework accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Process Management Suite accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Spatial Studio (component: Install issues (Apache Log4j)).  Supported versions that are affected are 23.2.1 and  24.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Spatial Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Spatial Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Management Cloud Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications BRM - Elastic Charging Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Apache Log4j)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Apache Log4j)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Apache Log4j)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications (component: XMPP Server (Apache Log4j)).   The supported version that is affected is 10.0.1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Instant Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications (component: NM Core (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Offline Mediation Controller accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Apache Log4j)).  Supported versions that are affected are 8.0.0, 7.5.0 and  7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Order and Service Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Management (Apache Log4j)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Performance Intelligence Center accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Log4j)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Apache Log4j)).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Log4j)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Log4j)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Policy Engine (Apache Log4j)).  Supported versions that are affected are 4.0.0-4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences Information Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Apache Log4j)).  Supported versions that are affected are 8.2.0.0-8.2.0.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Log4j)).  Supported versions that are affected are 5.0.0.0-5.0.9.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Master Person Index accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Bulk Data Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Log4j)).  Supported versions that are affected are 21.0.0-25.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Extract Tranform and Load product of Oracle Retail Applications (component: Mathematical Operators (Apache Log4j)).   The supported version that is affected is 13.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Extract Tranform and Load.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Extract Tranform and Load accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Integration Bus accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: EBS Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Price Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Service Backbone accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Apache Log4j)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Log4j)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Log4j)).  Supported versions that are affected are 21.12-21.12.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues (Apache Log4j)).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Log4j)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of GoldenGate Stream Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch Request (Apache Log4j)).  Supported versions that are affected are 8.0.0.7.0-8.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Service Catalog and Design accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Apache Log4j)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as  unauthorized read access to a subset of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Log4j)).   The supported version that is affected is 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Model Management and Governance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-10605V-21.12-21.12.17",
                    "P-1980V-14.1.2.1.0",
                    "P-4516V-7.7.0",
                    "P-13600V-23.2.1",
                    "P-9742V-15.2.0.0.0",
                    "P-4440V-3.6",
                    "P-2270V-7.4.1",
                    "P-5325V-12.2.1.4.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-14117V-25.2.200",
                    "P-10198V-12.2.1.4.0",
                    "P-5242V-12.2.1.4.0",
                    "P-2269V-15.0.0.0.0-15.2.0.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-9348V-11.4.0",
                    "P-14276V-8.1.2.7",
                    "P-14277V-25.2.200",
                    "P-11044V-10.5.0.2.0",
                    "P-2245V-4.5.0.2.0",
                    "P-10354V-23.12.0-23.12.16",
                    "P-10867V-16.0.3",
                    "P-5242V-14.1.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-2245V-25.10",
                    "P-12968V-16.0.3",
                    "P-10722V-19.0.1",
                    "P-2270V-7.5.0",
                    "P-9387V-3.6.1",
                    "P-4516V-7.6.0",
                    "P-13600V-24.2",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14119V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14392V-8.1.2.9",
                    "P-1980V-12.2.1.4.0",
                    "P-9742V-15.0.0.0.0",
                    "P-4461V-9.3.6",
                    "P-4516V-8.0.1",
                    "P-11513V-21.0.5-25.0.1",
                    "P-10867V-19.0.1",
                    "P-5680V-8.1.2.5.0",
                    "P-2545V-12.2.1.4.0",
                    "P-10198V-14.1.2.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-8495V-10.0.1.8.0",
                    "P-12968V-19.0.1",
                    "P-11044V-10.5.0.1.0",
                    "P-1824V-16.0.3",
                    "P-1807V-16.0.3",
                    "P-10354V-24.12.0-24.12.14",
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-2283V-8.0.0.7.0-8.3.0.3.0",
                    "P-13784V-7.0.0.0.8",
                    "P-10354V-25.12.0-25.12.6",
                    "P-5325V-14.1.2.0.0",
                    "P-1807V-19.0.1",
                    "P-5680V-8.0.8.7.0",
                    "P-2245V-4.3.0.6.0",
                    "P-4516V-7.5.0",
                    "P-2545V-14.1.1.0.0",
                    "P-4516V-7.5.1",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14121V-25.2.200",
                    "P-2245V-26.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-10900V-15.0.0.0",
                    "P-2270V-8.0.0",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-8575V-5.0.0.0-5.0.9.6",
                    "P-5242V-14.1.2.0.0",
                    "P-2245V-4.5.0.0.0",
                    "P-1803V-13.2.8",
                    "P-4379V-21.8.1.0.0",
                    "P-11166V-13.5.4.0.0-13.5.5.0.0",
                    "P-9742V-15.1.0.0.0",
                    "P-9161V-8.2.0.0-8.2.0.7",
                    "P-10354V-21.12.0-21.12.17",
                    "P-13784V-7.0.0.1.7",
                    "P-5680V-8.0.7.9.0",
                    "P-9177V-4.0.0-4.0.2",
                    "P-8496V-8.1.0.0",
                    "P-4516V-7.8.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-9742V-15.0.1.0.0",
                    "P-11516V-21.0.0-25.0.0",
                    "P-2245V-4.4.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-2545V-15.1.1.0.0",
                    "P-2245V-25.4",
                    "P-14252V-25.2.0.0.0",
                    "P-2245V-4.5.0.1.1",
                    "P-10722V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-5242V-15.1.1.0.0",
                    "P-10354V-22.12.0-22.12.15",
                    "P-2245V-4.5.0.1.3",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-5760V-19.1.0.0.0-19.1.0.0.22",
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6",
                        "P-4440V-3.6",
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                        "P-13600V-23.2.1",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-4379V-21.8.1.0.0",
                        "P-13600V-24.2",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11166V-13.5.4.0.0-13.5.5.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5325V-14.1.2.0.0",
                        "P-1980V-14.1.2.1.0",
                        "P-2545V-12.2.1.4.0",
                        "P-10198V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-5242V-14.1.2.0.0",
                        "P-5325V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0",
                        "P-5242V-15.1.1.0.0",
                        "P-1980V-12.2.1.4.0",
                        "P-5242V-14.1.1.0.0",
                        "P-2545V-15.1.1.0.0",
                        "P-10198V-12.2.1.4.0",
                        "P-5242V-12.2.1.4.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10605V-21.12-21.12.17",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-4.4.0.0.0",
                        "P-13784V-25.4.0.0.3",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-25.4",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-2245V-26.4",
                        "P-2245V-25.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8495V-10.0.1.8.0",
                        "P-8496V-8.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU219"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2269V-15.0.0.0.0-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU228"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-8.0.0",
                        "P-2270V-7.5.0",
                        "P-2270V-7.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9161V-8.2.0.0-8.2.0.7",
                        "P-8575V-5.0.0.0-5.0.9.6",
                        "P-9177V-4.0.0-4.0.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU271"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-12968V-19.0.1",
                        "P-11516V-21.0.0-25.0.0",
                        "P-1803V-13.2.8",
                        "P-11513V-21.0.5-25.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1824V-16.0.3",
                        "P-12968V-16.0.3",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0.0.7.0-8.3.0.3.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14276V-8.1.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU283"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0",
                        "P-4461V-9.3.6",
                        "P-4440V-3.6",
                        "P-4379V-21.8.1.0.0",
                        "P-11166V-13.5.4.0.0-13.5.5.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-68431",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39081823"
                },
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39081825"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle (libheif)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Enterprise Capture and  unauthorized read access to a subset of Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XML Publisher (libheif)).  Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools and  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-5085V-8.61",
                    "P-10212V-12.2.1.4.0",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0",
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-68480",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39001623"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Marshmallow)).  Supported versions that are affected are 22.3-26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-6965",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38990566"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (React)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2025-70873",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
                    "text": "39399989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39399985"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39399996"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (SQLite)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications (component: Core (SQLite)).   The supported version that is affected is 8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Messaging Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (SQLite)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14392V-8.1.2.9",
                    "P-14277V-25.2.200",
                    "P-8496V-8.1.0.0"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8496V-8.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU219"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14392V-8.1.2.9",
                        "P-14277V-25.2.200",
                        "P-8496V-8.1.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-7962",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
                    "text": "39445375"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39227774"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Java VM (Jakarta Mail) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.30 and  23.4.0-23.26.1. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via SMTP to compromise Java VM (Jakarta Mail).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Java VM (Jakarta Mail) accessible data. CVSS 3.1 Base Score 5.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Jakarta Mail)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Data Quality accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Java VM)V-19.3-19.30",
                    "P-5(Java VM)V-23.4.0-23.26.1",
                    "P-9464V-12.2.1.4.0",
                    "P-9464V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Java VM)V-23.4.0-23.26.1",
                        "P-5(Java VM)V-19.3-19.30"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9464V-12.2.1.4.0",
                        "P-9464V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Java VM)V-23.4.0-23.26.1",
                        "P-5(Java VM)V-19.3-19.30"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9464V-12.2.1.4.0",
                        "P-9464V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-8176",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "38645299"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "38645294"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (LibTIFF)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (LibTIFF)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14277V-24.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-24.2.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2025-8177",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "38645299"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "38645294"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (LibTIFF)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (LibTIFF)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14277V-24.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-24.2.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2025-8837",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39145828"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39145827"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39145823"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (JasPer)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Exposure Function executes to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (JasPer)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (JasPer)).  Supported versions that are affected are 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14117V-25.2.100",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.2.200",
                    "P-14117V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5",
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-8869",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "inline_mitigations_already_exist",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39616347"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: CNE (pip)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-14974V-25.2.200",
                    "P-14974V-25.1.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-8885",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-10945V-23.8.0-23.26.1"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
                    "text": "39237346"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: OGG Orchestration Service (Bouncy Castle Java FIPS)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-10945V-23.8.0-23.26.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10945V-23.8.0-23.26.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10945V-23.8.0-23.26.1"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-10945V-23.8.0-23.26.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-8916",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-10945V-23.8.0-23.26.1"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
                    "text": "39237346"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "38946145"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Bouncy Castle Java Library)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: OGG Orchestration Service (Bouncy Castle Java FIPS)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1",
                    "P-9019V-17.0-26.5"
                ],
                "known_not_affected": [
                    "P-10945V-23.8.0-23.26.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10945V-23.8.0-23.26.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10945V-23.8.0-23.26.1"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-10945V-23.8.0-23.26.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-8961",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "38645299"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "38645294"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (LibTIFF)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (LibTIFF)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14277V-24.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-24.2.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2025-9624",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39060725"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (OpenSearch)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2025-9900",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "38645299"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "38645294"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (LibTIFF)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (LibTIFF)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14277V-24.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-24.2.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14277V-24.2.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-0540",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39114090"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (DOMPurify)).  Supported versions that are affected are 4.3.0.5.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0-4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Application Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Application Framework accessible data as well as  unauthorized read access to a subset of Oracle Utilities Application Framework accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2245V-4.3.0.5.0-4.3.0.6.0",
                    "P-2245V-4.5.0.0.0-4.5.0.1.1",
                    "P-2245V-4.5.0.1.3",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-2245V-4.5.0.2.0",
                    "P-2245V-25.4",
                    "P-2245V-26.4",
                    "P-2245V-25.10",
                    "P-2245V-4.4.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.3.0.5.0-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0-4.5.0.1.1",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-25.4",
                        "P-2245V-26.4",
                        "P-2245V-25.10",
                        "P-2245V-4.4.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2245V-4.3.0.5.0-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0-4.5.0.1.1",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-25.4",
                        "P-2245V-26.4",
                        "P-2245V-25.10",
                        "P-2245V-4.4.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-0636",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39229496"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39229488"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Bouncy Castle Java Library)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle Management NextGen OUI Framework accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Bouncy Castle Java Library)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-12738V-14.1.2.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-12738V-14.1.2.1.0",
                    "P-12738V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ]
        },
        {
            "cve": "CVE-2026-0861",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687789"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (glibc)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Certificate Management executes to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14868V-25.2.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-0964",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464356"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39464357"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464359"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464360"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464361"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464362"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Slice Selection Function executes to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (libssh)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14277V-25.2.200",
                    "P-14117V-25.2.200",
                    "P-14117V-25.1.200",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14122V-24.2.5",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-0965",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464356"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39464357"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464359"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464360"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464361"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464362"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Slice Selection Function executes to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (libssh)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14277V-25.2.200",
                    "P-14117V-25.2.200",
                    "P-14117V-25.1.200",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14122V-24.2.5",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-0966",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464356"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39464357"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464359"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464360"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464361"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464362"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Slice Selection Function executes to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (libssh)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14277V-25.2.200",
                    "P-14117V-25.2.200",
                    "P-14117V-25.1.200",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14122V-24.2.5",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-0967",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464356"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39464357"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464359"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464360"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464361"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464362"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Slice Selection Function executes to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (libssh)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14277V-25.2.200",
                    "P-14117V-25.2.200",
                    "P-14117V-25.1.200",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14122V-24.2.5",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-0968",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464356"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39464357"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464359"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464360"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464361"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464362"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Slice Selection Function executes to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libssh)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (libssh)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14277V-25.2.200",
                    "P-14117V-25.2.200",
                    "P-14117V-25.1.200",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14122V-24.2.5",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-1002",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483517"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Vert.x-Web)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 2.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-10879",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39576482"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-19.3-19.31",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-1225",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483471"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (logback)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of GoldenGate Stream Analytics accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 1.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-1229",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39056696"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (CIRCL)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-1605",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.1"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "39097509"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Graph Server and Client",
                    "text": "39226460"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39058558"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
                    "text": "39059478"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Eclipse Jetty)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Third Party (Eclipse Jetty)).   The supported version that is affected is 26.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Cloud Native Session Border Controller accessible data as well as  unauthorized access to critical data or complete access to all Oracle Cloud Native Session Border Controller accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Desktop Integration Siebel Agent (Eclipse Jetty)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM End User. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install issues (Eclipse Jetty)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-14.1.2.0.0",
                    "P-14762V-26.0.0",
                    "P-9011V-17.0-26.5"
                ],
                "known_not_affected": [
                    "P-14069V-25.4.1",
                    "P-14069V-26.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14762V-26.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU269"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4647V-14.1.2.0.0",
                        "P-9011V-17.0-26.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.1"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-21441",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "39145807"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39145783"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39145782"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39145777"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "39145764"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39145775"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "39145786"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
                    "text": "39145767"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39145789"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Origination",
                    "text": "39145768"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39145779"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39145801"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (urllib3)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (urllib3)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration (urllib3)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (urllib3)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (urllib3)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (urllib3)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (urllib3)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (urllib3)).  Supported versions that are affected are 25.1.200 and  25.2.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (urllib3)).  Supported versions that are affected are 9.0.0.0.0, 9.0.1.0.0 and  9.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (urllib3)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (urllib3)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Third Party (urllib3)).  Supported versions that are affected are 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.11, 2.6.0.2.0-2.6.0.2.8 and  25.12.0.0.0-25.12.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Network Management System. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-13304V-14.6.0-14.8.0",
                    "P-14117V-25.1.200",
                    "P-2241V-2.6.0.1.0-2.6.0.1.11",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-13701V-14.6.0-14.8.0",
                    "P-10899V-9.0.1.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.1.203",
                    "P-14325V-14.6.0-14.8.0",
                    "P-10761V-6.0",
                    "P-14121V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14392V-8.1.2.9",
                    "P-10899V-9.1.0.0.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-2241V-2.5.0.2.0-2.5.0.2.11",
                    "P-2241V-2.6.0.2.0-2.6.0.2.8",
                    "P-10899V-9.0.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.2.200",
                    "P-2241V-25.12.0.0.0-25.12.0.0.1"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14325V-14.6.0-14.8.0",
                        "P-13304V-14.6.0-14.8.0",
                        "P-13701V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.1.0.0.0",
                        "P-10899V-9.0.0.0.0",
                        "P-10899V-9.0.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-2.6.0.1.0-2.6.0.1.11",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.8",
                        "P-2241V-25.12.0.0.0-25.12.0.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5",
                        "P-13304V-14.6.0-14.8.0",
                        "P-14117V-25.1.200",
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                        "P-13701V-14.6.0-14.8.0",
                        "P-10899V-9.0.1.0.0",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.1.203",
                        "P-14325V-14.6.0-14.8.0",
                        "P-10761V-6.0",
                        "P-14121V-25.2.200",
                        "P-14117V-25.2.100",
                        "P-14392V-8.1.2.9",
                        "P-10899V-9.1.0.0.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1",
                        "P-10899V-9.0.0.0.0",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_ATS Framework)V-25.2.200"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2241V-2.6.0.1.0-2.6.0.1.11",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.8",
                        "P-2241V-25.12.0.0.0-25.12.0.0.1"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-21452",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483191"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (MessagePack)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 2.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-21636",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38875877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ]
        },
        {
            "cve": "CVE-2026-21637",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38875877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ]
        },
        {
            "cve": "CVE-2026-21710",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38875877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ]
        },
        {
            "cve": "CVE-2026-21953",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "38484274"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile).   The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11513V-21.0.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.3,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-11513V-21.0.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-21954",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "38484436"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile).   The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11513V-21.0.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-11513V-21.0.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-22007",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Default Component (FreeType)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-22013",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Default Component (FreeType)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-22016",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Default Component (FreeType)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-22018",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Default Component (FreeType)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-22021",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Default Component (FreeType)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-22029",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39698109"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Embedded Web UI for Services (React)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-22732",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39151504"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Development",
                    "text": "39201361"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Spring Security)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Virtual Account Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager (Spring Security)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Development accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Development accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13487V-14.6.0-14.8.0",
                    "P-9001V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9001V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13487V-14.6.0-14.8.0",
                        "P-9001V-17.0-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-22735",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39328995"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-12.2.1.4.0",
                    "P-4647V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0",
                        "P-4647V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ]
        },
        {
            "cve": "CVE-2026-22737",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39328995"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Development",
                    "text": "39201395"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager (Spring Framework)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Development accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-12.2.1.4.0",
                    "P-4647V-14.1.2.0.0",
                    "P-9001V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9001V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0",
                        "P-4647V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4647V-14.1.2.0.0",
                        "P-4647V-12.2.1.4.0",
                        "P-9001V-17.0-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-22747",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464713"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464704"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464710"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39464705"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464706"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464707"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39464718"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464708"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Security)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Security)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Security)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Security)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Security)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Utilities Testing Accelerator accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-14277V-25.1.200",
                    "P-14130V-25.2.200",
                    "P-14597V-6.1.1-7.0.0",
                    "P-13784V-25.4.0.0.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14121V-25.1.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                        "P-14392V-8.1.3.1",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-14277V-25.1.200",
                        "P-14130V-25.2.200",
                        "P-13784V-25.4.0.0.3"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-22748",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464713"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464704"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464710"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39464705"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464706"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464707"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39464718"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464708"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Security)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Security)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Security)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Security)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Security)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-14130V-25.2.200",
                    "P-14597V-6.1.1-7.0.0",
                    "P-13784V-25.4.0.0.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-22751",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464713"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464704"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464710"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39464705"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464706"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464707"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39464718"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464708"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Security)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Security)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Security)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Security)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Security)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-14130V-25.2.200",
                    "P-14597V-6.1.1-7.0.0",
                    "P-13784V-25.4.0.0.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-22753",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464713"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464704"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464710"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39464705"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464706"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464707"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39464718"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464708"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Security)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Security)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Security)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Security)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Security)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-14130V-25.2.200",
                    "P-14597V-6.1.1-7.0.0",
                    "P-13784V-25.4.0.0.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-22754",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464713"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464704"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464710"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39464705"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39464706"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464707"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39464718"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464708"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Security)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Security)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Security)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Security)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Security)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Security)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-14130V-25.2.200",
                    "P-14597V-6.1.1-7.0.0",
                    "P-13784V-25.4.0.0.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-22815",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-22860",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2026-2297",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-23270",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39384187"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Security (Linux Kernel)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Performance Intelligence Center executes to compromise Oracle Communications Performance Intelligence Center.  While the vulnerability is in Oracle Communications Performance Intelligence Center, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Performance Intelligence Center.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11044V-10.5.0.1.0",
                    "P-11044V-10.5.0.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                }
            ]
        },
        {
            "cve": "CVE-2026-2332",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39235705"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
                    "text": "39059478"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Third Party (Eclipse Jetty)).   The supported version that is affected is 26.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Cloud Native Session Border Controller accessible data as well as  unauthorized access to critical data or complete access to all Oracle Cloud Native Session Border Controller accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Eclipse Jetty)).  Supported versions that are affected are 21.3-21.20 and  23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle GoldenGate Big Data and Application Adapters accessible data as well as  unauthorized access to critical data or complete access to all Oracle GoldenGate Big Data and Application Adapters accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14762V-26.0.0",
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14762V-26.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU269"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14762V-26.0.0",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-23865",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.2",
                        "P-5(GraalVM Multilingual Engine)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39178204"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Default Component (FreeType)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ],
                "known_not_affected": [
                    "P-5(GraalVM Multilingual Engine)V-21.3-21.22",
                    "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.2",
                        "P-5(GraalVM Multilingual Engine)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.2",
                        "P-5(GraalVM Multilingual Engine)V-21.3-21.22"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14868V-25.2.200"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.2",
                        "P-5(GraalVM Multilingual Engine)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-23901",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39030731"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Shiro)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2026-23903",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39030731"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Shiro)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-23953",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2026-23954",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ]
        },
        {
            "cve": "CVE-2026-24051",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39056997"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39049626"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39020243"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (OpenTelemetry-Go)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (OpenTelemetry-Go)).  Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597(Oracle Communications Unified Assurance_Core)V-6.1.1-7.0.0",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597(Oracle Communications Unified Assurance_Core)V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597(Oracle Communications Unified Assurance_Core)V-6.1.1-7.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-24281",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "39225812"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39225833"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39225838"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "39225836"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39439560"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache ZooKeeper)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Corporate Lending Process Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: TimesTen Grid (Apache ZooKeeper)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: NMS Monitor (Apache ZooKeeper)).  Supported versions that are affected are 2.5.0.2.0-2.5.0.2.11 and  2.6.0.1.0-2.6.0.1.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Integration (Apache ZooKeeper)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Unifier accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache ZooKeeper)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all GoldenGate Stream Analytics accessible data as well as  unauthorized access to critical data or complete access to all GoldenGate Stream Analytics accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10354V-22.12.0-22.12.15",
                    "P-10354V-24.12.0-24.12.14",
                    "P-10354V-23.12.0-23.12.16",
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15",
                    "P-1870V-22.1.1.1.0",
                    "P-2241V-2.6.0.1.0-2.6.0.1.11",
                    "P-9019V-17.0-26.5",
                    "P-10354V-21.12.0-21.12.17",
                    "P-2241V-2.5.0.2.0-2.5.0.2.11",
                    "P-13701V-14.6.0-14.8.0",
                    "P-10354V-25.12.0-25.12.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13701V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15",
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-2.6.0.1.0-2.6.0.1.11",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-24308",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "39225812"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39225833"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39225838"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "39225836"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39094135"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Apache ZooKeeper)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache ZooKeeper)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Corporate Lending Process Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: TimesTen Grid (Apache ZooKeeper)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: NMS Monitor (Apache ZooKeeper)).  Supported versions that are affected are 2.5.0.2.0-2.5.0.2.11 and  2.6.0.1.0-2.6.0.1.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Integration (Apache ZooKeeper)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Unifier accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10354V-22.12.0-22.12.15",
                    "P-10354V-24.12.0-24.12.14",
                    "P-10354V-23.12.0-23.12.16",
                    "P-1870V-22.1.1.1.0",
                    "P-2241V-2.6.0.1.0-2.6.0.1.11",
                    "P-9019V-17.0-26.5",
                    "P-10354V-21.12.0-21.12.17",
                    "P-2241V-2.5.0.2.0-2.5.0.2.11",
                    "P-13701V-14.6.0-14.8.0",
                    "P-10354V-25.12.0-25.12.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13701V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-2.6.0.1.0-2.6.0.1.11",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-1870V-22.1.1.1.0",
                        "P-2241V-2.6.0.1.0-2.6.0.1.11",
                        "P-9019V-17.0-26.5",
                        "P-10354V-21.12.0-21.12.17",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-13701V-14.6.0-14.8.0",
                        "P-10354V-25.12.0-25.12.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-24400",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-1032V-12.2.1.4.0",
                        "P-1032V-14.1.2.0.0"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
                    "text": "39559337"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39015983"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39096932"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39096995"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (assertj)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST (jackson-core)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (jackson-core)).  Supported versions that are affected are 17.0-26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Fusion Middleware (component: Oracle Database Client for Fusion Middleware (assertj)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0",
                    "P-9019V-17.0-26.4",
                    "P-9008V-17.0-26.5"
                ],
                "known_not_affected": [
                    "P-1032V-12.2.1.4.0",
                    "P-1032V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.4",
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1032V-12.2.1.4.0",
                        "P-1032V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.4",
                        "P-9008V-17.0-26.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1032V-12.2.1.4.0",
                        "P-1032V-14.1.2.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-1032V-12.2.1.4.0",
                        "P-1032V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-24734",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39261471"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel Apps - Marketing",
                    "text": "39105048"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing (Apache Tomcat)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Marketing accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8974V-17.0-26.5",
                    "P-11513V-21.0.5-25.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8974V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.5-25.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8974V-17.0-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-24842",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38990566"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (React)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-25526",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39439416"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (JinJava)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-25639",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39698031"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Embedded Web UI for Services (Axios)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-25645",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-25854",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39226171"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-26007",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39039565"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Cryptography)).  Supported versions that are affected are 22.3-26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-2673",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39196912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Trace file analyzer (Python)).  Supported versions that are affected are 26.2.0 and  26.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14634V-26.3.0",
                    "P-14634V-26.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.0",
                        "P-14634V-26.2.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-26960",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38990566"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (React)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-17.0-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-27099",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39052236"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Jenkins)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14130V-25.2.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-27100",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39052236"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Jenkins)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                }
            ]
        },
        {
            "cve": "CVE-2026-27135",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39422829"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39422828"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39422830"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39422841"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39422852"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39422850"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
                    "text": "39422812"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39422833"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39422844"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39422843"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39422831"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
                    "text": "39631928"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39422827"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39422815"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39422826"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
                    "text": "39422846"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (Nghttp2)).  Supported versions that are affected are 5.1.0, 5.0.0 and  4.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Nghttp2)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Management Cloud Engine. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Nghttp2)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Nghttp2)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: NRF (Nghttp2)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Nghttp2)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Nghttp2)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Nghttp2)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Nghttp2)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Nghttp2)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Management (Nghttp2)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Performance Intelligence Center.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Performance Intelligence Center. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Nghttp2)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (Nghttp2)).  Supported versions that are affected are 9.3.0, 10.0.0 and  10.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Nghttp2)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Nghttp2)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Console (Nghttp2)).  Supported versions that are affected are 25.1.203 and  25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-10750V-10.1.0",
                    "P-10750V-10.0.0",
                    "P-14250V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-14547V-24.2.0",
                    "P-14547V-24.3.4",
                    "P-10750V-9.3.0",
                    "P-14547V-25.2.200",
                    "P-14121V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14547V-25.2.100",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-14117V-25.2.200",
                    "P-14250V-25.1.203",
                    "P-4516V-8.0.1",
                    "P-14252V-25.2.0.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-14277V-25.2.200",
                    "P-10758V-4.2.0",
                    "P-14117V-25.1.200",
                    "P-14547V-25.1.200",
                    "P-10900V-15.0.0.0",
                    "P-11044V-10.5.0.2.0",
                    "P-11044V-10.5.0.1.0",
                    "P-10758V-5.1.0",
                    "P-10758V-5.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_NRF)V-25.2.201",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10758V-4.2.0",
                        "P-10758V-5.1.0",
                        "P-10758V-5.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU234"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_NRF)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10750V-10.1.0",
                        "P-10750V-10.0.0",
                        "P-10750V-9.3.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU233"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14250V-25.2.201",
                        "P-14250V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU246"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5",
                        "P-10750V-10.1.0",
                        "P-10750V-10.0.0",
                        "P-14250V-25.2.201",
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4",
                        "P-10750V-9.3.0",
                        "P-14547V-25.2.200",
                        "P-14121V-25.2.200",
                        "P-14117V-25.2.100",
                        "P-14547V-25.2.100",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14117V-25.2.200",
                        "P-14250V-25.1.203",
                        "P-4516V-8.0.1",
                        "P-14252V-25.2.0.0.0",
                        "P-14597V-6.1.1-7.0.0",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                        "P-14277V-25.2.200",
                        "P-10758V-4.2.0",
                        "P-14117V-25.1.200",
                        "P-14547V-25.1.200",
                        "P-10900V-15.0.0.0",
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0",
                        "P-10758V-5.1.0",
                        "P-10758V-5.0.0",
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_NRF)V-25.2.201",
                        "P-14130V-25.2.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-27141",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
                    "text": "39050166"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Security (Golang Go)).   The supported version that is affected is 26.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Cloud Native Session Border Controller. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14762V-26.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14762V-26.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU269"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14762V-26.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-27171",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39400033"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39400034"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39400031"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39400053"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39400032"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39400041"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39400028"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Perl)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Perl)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Perl)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: perf-info (Perl)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Perl)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Perl)).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                    "P-14277V-25.2.200",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-1870V-26.1.1.1.0",
                    "P-14130V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-14117V-25.2.100",
                    "P-5(RDBMS)V-19.3-19.31",
                    "P-14117V-25.1.200",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-1870V-26.1.1.1.0",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14117V-25.2.100",
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-14117V-25.1.200",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-27205",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39056787"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Flask)).  Supported versions that are affected are 22.3-26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-27601",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39549136"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39226533"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Business Control Center (underscore)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (underscore)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-27727",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Veridata",
                    "text": "39164229"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Veridata product of Oracle GoldenGate (component: Server (Mchange Commons Java)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-28386",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687587"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-28387",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687587"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39196912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Trace file analyzer (Python)).  Supported versions that are affected are 26.2.0 and  26.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200",
                    "P-14634V-26.3.0",
                    "P-14634V-26.2.0",
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.0",
                        "P-14634V-26.2.0",
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14634V-26.3.0",
                        "P-14634V-26.2.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-28388",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687587"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39196912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Trace file analyzer (Python)).  Supported versions that are affected are 26.2.0 and  26.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200",
                    "P-14634V-26.3.0",
                    "P-14634V-26.2.0",
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.0",
                        "P-14634V-26.2.0",
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-28389",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687587"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39196912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Trace file analyzer (Python)).  Supported versions that are affected are 26.2.0 and  26.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200",
                    "P-14634V-26.3.0",
                    "P-14634V-26.2.0",
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.0",
                        "P-14634V-26.2.0",
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-28390",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687587"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39196912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Trace file analyzer (Python)).  Supported versions that are affected are 26.2.0 and  26.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200",
                    "P-14634V-26.3.0",
                    "P-14634V-26.2.0",
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.0",
                        "P-14634V-26.2.0",
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14868V-25.2.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-29062",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39089386"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Third Party (jackson-core)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2245V-4.5.0.1.3",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-2245V-4.5.0.1.1",
                    "P-2245V-4.5.0.2.0",
                    "P-2245V-25.4",
                    "P-2245V-26.4",
                    "P-2245V-4.3.0.6.0",
                    "P-2245V-4.5.0.0.0",
                    "P-2245V-25.10",
                    "P-2245V-4.4.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-25.4",
                        "P-2245V-26.4",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-25.10",
                        "P-2245V-4.4.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-25.4",
                        "P-2245V-26.4",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-25.10",
                        "P-2245V-4.4.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-29145",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39226171"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39261471"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39261452"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39261454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39261457"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Tomcat)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Tomcat)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-14277V-25.2.200",
                    "P-9008V-17.0-26.5",
                    "P-11513V-21.0.5-25.0.1",
                    "P-10900V-15.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.5-25.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                }
            ]
        },
        {
            "cve": "CVE-2026-29167",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14277V-25.2.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-29170",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-2950",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39293057"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "39293038"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39293055"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39293067"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39293111"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39293095"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39293052"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39293074"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39293118"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Graph Server and Client",
                    "text": "39293092"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Lodash)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Lodash)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Lodash)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Lodash)).  Supported versions that are affected are 24.2.0.0.1, 24.3.4 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Lodash)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Lodash)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Compliance Studio.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install issues (Lodash)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Lodash)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Lodash)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Integration (Lodash)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in takeover of Primavera Unifier.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5680V-8.1.2.5.0",
                    "P-14277V-25.2.200",
                    "P-14547V-25.1.200",
                    "P-5680V-8.0.8.7.0",
                    "P-13701V-14.6.0-14.8.0",
                    "P-14547V-24.3.4",
                    "P-13784V-25.4.0.0.3",
                    "P-10354V-22.12.0-22.12.15",
                    "P-10354V-24.12.0-24.12.14",
                    "P-10354V-23.12.0-23.12.16",
                    "P-14121V-25.2.200",
                    "P-14547V-24.2.0.0.1",
                    "P-14392V-8.1.2.9",
                    "P-11705V-23.2",
                    "P-11705V-23.1",
                    "P-10354V-21.12.0-21.12.17",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-5680V-8.0.7.9.0",
                    "P-10354V-25.12.0-25.12.6"
                ],
                "known_not_affected": [
                    "P-14069V-25.4.2",
                    "P-14069V-26.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13701V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-30922",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39342022"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Python)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14119V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14119V-25.2.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-31402",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39384187"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Security (Linux Kernel)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Performance Intelligence Center executes to compromise Oracle Communications Performance Intelligence Center.  While the vulnerability is in Oracle Communications Performance Intelligence Center, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Performance Intelligence Center.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11044V-10.5.0.1.0",
                    "P-11044V-10.5.0.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                }
            ]
        },
        {
            "cve": "CVE-2026-31431",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39384187"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "39322316"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: PMAC (Linux Kernel)).  Supported versions that are affected are 9.0.0.0.0, 9.1.0.0.0, 9.2.0.0.0 and  9.3.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Security (Linux Kernel)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Performance Intelligence Center executes to compromise Oracle Communications Performance Intelligence Center.  While the vulnerability is in Oracle Communications Performance Intelligence Center, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Performance Intelligence Center.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.2.0.0.0",
                    "P-11044V-10.5.0.1.0",
                    "P-10899V-9.0.0.0.0",
                    "P-10899V-9.1.0.0.0",
                    "P-11044V-10.5.0.2.0",
                    "P-10899V-9.3.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.2.0.0.0",
                        "P-10899V-9.1.0.0.0",
                        "P-10899V-9.3.0.0.0",
                        "P-10899V-9.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10899V-9.2.0.0.0",
                        "P-10899V-9.1.0.0.0",
                        "P-10899V-9.3.0.0.0",
                        "P-10899V-9.0.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-31789",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687587"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39196912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Trace file analyzer (Python)).  Supported versions that are affected are 26.2.0 and  26.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200",
                    "P-14634V-26.3.0",
                    "P-14634V-26.2.0",
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.0",
                        "P-14634V-26.2.0",
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-31790",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39603974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687587"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39196912"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Trace file analyzer (Python)).  Supported versions that are affected are 26.2.0 and  26.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (OpenSSL)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200",
                    "P-14634V-26.3.0",
                    "P-14634V-26.2.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.0",
                        "P-14634V-26.2.0",
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-3219",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-33186",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39108266"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (gRPC)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-33557",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "39276837"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39276859"
                },
                {
                    "system_name": "Oracle Bug ID of SQL Developer",
                    "text": "39276891"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
                    "text": "39276829"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
                    "text": "39276890"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39276892"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39276851"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39276862"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39276850"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Origination",
                    "text": "39276844"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39276854"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Apache Kafka)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Data Quality accessible data as well as  unauthorized access to critical data or complete access to all Oracle Enterprise Data Quality accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache Kafka)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Corporate Lending Process Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Corporate Lending Process Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration (Apache Kafka)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Origination accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Origination accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Apache Kafka)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Apache Kafka)).  Supported versions that are affected are 25.1.200 and  25.2.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Third Party (Apache Kafka)).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Third Party (Apache Kafka)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access (Apache Kafka)).  Supported versions that are affected are 21.12.0.0-21.12.21.8, 22.12.0.0-22.12.21.2, 23.12.0-23.12.19, 24.12.0-24.12.14 and  25.12.0-25.12.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the SQL Developer product of Oracle SQL Developer (component: Installation (Apache Kafka)).  Supported versions that are affected are 19.3-24.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all SQL Developer accessible data as well as  unauthorized access to critical data or complete access to all SQL Developer accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Third Party (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-5680V-8.0.8.7.0",
                    "P-5579V-25.12.0-25.12.4",
                    "P-1875(SQL Developer_Installation)V-19.3-24.3",
                    "P-4516V-7.5.0",
                    "P-4516V-7.5.1",
                    "P-4516V-7.6.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14325V-14.6.0-14.8.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14117V-25.2.100",
                    "P-4516V-8.0.1",
                    "P-5579V-21.12.0.0-21.12.21.8",
                    "P-9464V-12.2.1.4.0",
                    "P-5680V-8.1.2.5.0",
                    "P-14117V-25.1.200",
                    "P-5579V-24.12.0-24.12.14",
                    "P-5579V-23.12.0-23.12.19",
                    "P-5579V-22.12.0.0-22.12.21.2",
                    "P-13701V-14.6.0-14.8.0",
                    "P-9464V-14.1.2.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-5680V-8.0.7.9.0"
                ],
                "known_not_affected": [
                    "P-14547V-25.2.200",
                    "P-14547V-24.2.0.0.1",
                    "P-14547V-25.2.100",
                    "P-14547V-25.1.200",
                    "P-14547V-24.3.4",
                    "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9464V-12.2.1.4.0",
                        "P-9464V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14325V-14.6.0-14.8.0",
                        "P-13701V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5579V-25.12.0-25.12.4",
                        "P-5579V-24.12.0-24.12.14",
                        "P-5579V-23.12.0-23.12.19",
                        "P-5579V-22.12.0.0-22.12.21.2",
                        "P-5579V-21.12.0.0-21.12.21.8"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1875(SQL Developer_Installation)V-19.3-24.3",
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5579V-25.12.0-25.12.4",
                        "P-1875(SQL Developer_Installation)V-19.3-24.3",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                        "P-14325V-14.6.0-14.8.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-14117V-25.2.100",
                        "P-4516V-8.0.1",
                        "P-5579V-21.12.0.0-21.12.21.8",
                        "P-9464V-12.2.1.4.0",
                        "P-5680V-8.1.2.5.0",
                        "P-14117V-25.1.200",
                        "P-5579V-24.12.0-24.12.14",
                        "P-5579V-23.12.0-23.12.19",
                        "P-5579V-22.12.0.0-22.12.21.2",
                        "P-13701V-14.6.0-14.8.0",
                        "P-9464V-14.1.2.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-5680V-8.0.7.9.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14547V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4",
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-33636",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39197711"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Java SE (component: 2D (libpng)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-3381",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39400033"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39400034"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39400031"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39400053"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39400032"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39400041"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39400028"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Perl)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Perl)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Perl)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: perf-info (Perl)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Perl)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Perl)).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                    "P-14277V-25.2.200",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-1870V-26.1.1.1.0",
                    "P-14130V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-14117V-25.2.100",
                    "P-5(RDBMS)V-19.3-19.31",
                    "P-14117V-25.1.200",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-1870V-26.1.1.1.0",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14117V-25.2.100",
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-14117V-25.1.200",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-33870",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Veridata",
                    "text": "39119198"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39482563"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Veridata product of Oracle GoldenGate (component: Thirdparty Jars (Netty)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Netty)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  While the vulnerability is in GoldenGate Stream Analytics, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of GoldenGate Stream Analytics accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-13487V-14.5.0-14.8.0"
                ],
                "known_not_affected": [
                    "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0",
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5758V-23.1.0.0.0-23.26.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-33871",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39196688"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39482563"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Third Party (Netty)).  Supported versions that are affected are 21.3-21.20 and  23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Big Data and Application Adapters. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Netty)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  While the vulnerability is in GoldenGate Stream Analytics, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of GoldenGate Stream Analytics accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-21.3-21.20"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 3.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34073",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34180",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-34181",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-34182",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-34183",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-34268",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Default Component (FreeType)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-34282",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Default Component (FreeType)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-34316",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Service Center",
                    "text": "39089307"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Service Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Service Center accessible data as well as  unauthorized read access to a subset of Oracle Commerce Service Center accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9351V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9351V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9351V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34355",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-34356",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-34477",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39399100"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39399068"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Spatial Studio",
                    "text": "39398854"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Price Management",
                    "text": "39399108"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39398930"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
                    "text": "39398851"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39398935"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39398934"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39398932"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39198313"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39398938"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39398937"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39499467"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Extract Tranform and Load",
                    "text": "39399096"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399097"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
                    "text": "39742428"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39399132"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39398924"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39398928"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39398927"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39398926"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39499517"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
                    "text": "39399048"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Bulk Data Integration",
                    "text": "39399086"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39399043"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39399121"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39398953"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39398997"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39398952"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39398950"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
                    "text": "39399049"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Gateway",
                    "text": "39399127"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39213017"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39360371"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39398958"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39212120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail EFTLink",
                    "text": "39399094"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483308"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
                    "text": "39399051"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39399111"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39399114"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39398864"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39298054"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39398863"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
                    "text": "39398944"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39398988"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Instant Messaging Server",
                    "text": "39398943"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
                    "text": "39398949"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39198321"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39278469"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Analysis Tool (Apache Log4j)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Log4j)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Log4j)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Log4j)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Log4j)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Application Framework accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Process Management Suite accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Spatial Studio (component: Install issues (Apache Log4j)).  Supported versions that are affected are 23.2.1 and  24.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Spatial Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Spatial Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Management Cloud Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications BRM - Elastic Charging Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Apache Log4j)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Apache Log4j)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Apache Log4j)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications (component: XMPP Server (Apache Log4j)).   The supported version that is affected is 10.0.1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Instant Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications (component: NM Core (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Offline Mediation Controller accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Apache Log4j)).  Supported versions that are affected are 8.0.0, 7.5.0 and  7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Order and Service Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Management (Apache Log4j)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Performance Intelligence Center accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Log4j)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Apache Log4j)).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Log4j)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Log4j)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Policy Engine (Apache Log4j)).  Supported versions that are affected are 4.0.0-4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences Information Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Apache Log4j)).  Supported versions that are affected are 8.2.0.0-8.2.0.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Log4j)).  Supported versions that are affected are 5.0.0.0-5.0.9.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Master Person Index accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Bulk Data Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Log4j)).  Supported versions that are affected are 21.0.0-25.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Extract Tranform and Load product of Oracle Retail Applications (component: Mathematical Operators (Apache Log4j)).   The supported version that is affected is 13.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Extract Tranform and Load.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Extract Tranform and Load accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Integration Bus accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: EBS Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Price Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Service Backbone accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Apache Log4j)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Log4j)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Log4j)).  Supported versions that are affected are 21.12-21.12.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues (Apache Log4j)).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Log4j)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of GoldenGate Stream Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch Request (Apache Log4j)).  Supported versions that are affected are 8.0.0.7.0-8.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Service Catalog and Design accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Log4j)).   The supported version that is affected is 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Model Management and Governance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-10605V-21.12-21.12.17",
                    "P-1980V-14.1.2.1.0",
                    "P-4516V-7.7.0",
                    "P-13600V-23.2.1",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.4.1",
                    "P-5325V-12.2.1.4.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-14117V-25.2.200",
                    "P-10198V-12.2.1.4.0",
                    "P-5242V-12.2.1.4.0",
                    "P-2269V-15.0.0.0.0-15.2.0.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-14276V-8.1.2.7",
                    "P-14277V-25.2.200",
                    "P-11044V-10.5.0.2.0",
                    "P-2245V-4.5.0.2.0",
                    "P-10354V-23.12.0-23.12.16",
                    "P-10867V-16.0.3",
                    "P-5242V-14.1.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-2245V-25.10",
                    "P-12968V-16.0.3",
                    "P-10722V-19.0.1",
                    "P-2270V-7.5.0",
                    "P-9387V-3.6.1",
                    "P-4516V-7.6.0",
                    "P-13600V-24.2",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14119V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14392V-8.1.2.9",
                    "P-1980V-12.2.1.4.0",
                    "P-9742V-15.0.0.0.0",
                    "P-4516V-8.0.1",
                    "P-11513V-21.0.5-25.0.1",
                    "P-10867V-19.0.1",
                    "P-5680V-8.1.2.5.0",
                    "P-2545V-12.2.1.4.0",
                    "P-10198V-14.1.2.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-8495V-10.0.1.8.0",
                    "P-12968V-19.0.1",
                    "P-11044V-10.5.0.1.0",
                    "P-1824V-16.0.3",
                    "P-1807V-16.0.3",
                    "P-10354V-24.12.0-24.12.14",
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-2283V-8.0.0.7.0-8.3.0.3.0",
                    "P-4647V-12.2.1.4.0",
                    "P-13784V-7.0.0.0.8",
                    "P-10354V-25.12.0-25.12.6",
                    "P-5325V-14.1.2.0.0",
                    "P-1807V-19.0.1",
                    "P-5680V-8.0.8.7.0",
                    "P-2245V-4.3.0.6.0",
                    "P-4516V-7.5.0",
                    "P-2545V-14.1.1.0.0",
                    "P-4516V-7.5.1",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14121V-25.2.200",
                    "P-2245V-26.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-10900V-15.0.0.0",
                    "P-2270V-8.0.0",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-8575V-5.0.0.0-5.0.9.6",
                    "P-5242V-14.1.2.0.0",
                    "P-2245V-4.5.0.0.0",
                    "P-1803V-13.2.8",
                    "P-9742V-15.1.0.0.0",
                    "P-9161V-8.2.0.0-8.2.0.7",
                    "P-10354V-21.12.0-21.12.17",
                    "P-13784V-7.0.0.1.7",
                    "P-5680V-8.0.7.9.0",
                    "P-9177V-4.0.0-4.0.2",
                    "P-8496V-8.1.0.0",
                    "P-4516V-7.8.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-9742V-15.0.1.0.0",
                    "P-11516V-21.0.0-25.0.0",
                    "P-2245V-4.4.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-2545V-15.1.1.0.0",
                    "P-2245V-25.4",
                    "P-14252V-25.2.0.0.0",
                    "P-2245V-4.5.0.1.1",
                    "P-10722V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-5242V-15.1.1.0.0",
                    "P-10354V-22.12.0-22.12.15",
                    "P-2245V-4.5.0.1.3",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-5760V-19.1.0.0.0-19.1.0.0.22",
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5325V-14.1.2.0.0",
                        "P-1980V-14.1.2.1.0",
                        "P-2545V-12.2.1.4.0",
                        "P-10198V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-5242V-14.1.2.0.0",
                        "P-5325V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0",
                        "P-5242V-15.1.1.0.0",
                        "P-1980V-12.2.1.4.0",
                        "P-5242V-14.1.1.0.0",
                        "P-2545V-15.1.1.0.0",
                        "P-10198V-12.2.1.4.0",
                        "P-4647V-12.2.1.4.0",
                        "P-5242V-12.2.1.4.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10605V-21.12-21.12.17",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-4.4.0.0.0",
                        "P-13784V-25.4.0.0.3",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-25.4",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-2245V-26.4",
                        "P-2245V-25.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                        "P-13600V-23.2.1",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-13600V-24.2",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8495V-10.0.1.8.0",
                        "P-8496V-8.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU219"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2269V-15.0.0.0.0-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU228"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-8.0.0",
                        "P-2270V-7.5.0",
                        "P-2270V-7.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9161V-8.2.0.0-8.2.0.7",
                        "P-8575V-5.0.0.0-5.0.9.6",
                        "P-9177V-4.0.0-4.0.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU271"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-12968V-19.0.1",
                        "P-11516V-21.0.0-25.0.0",
                        "P-1803V-13.2.8",
                        "P-11513V-21.0.5-25.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1824V-16.0.3",
                        "P-12968V-16.0.3",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0.0.7.0-8.3.0.3.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14276V-8.1.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU283"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34478",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "inline_mitigations_already_exist",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39399100"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39399068"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Spatial Studio",
                    "text": "39398854"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Price Management",
                    "text": "39399108"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39398930"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
                    "text": "39398851"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39398935"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39398934"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39398932"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39198313"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39398938"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39398937"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39499467"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Extract Tranform and Load",
                    "text": "39399096"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399097"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
                    "text": "39742428"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39399132"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39398924"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39398928"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39398927"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39398926"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39199679"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
                    "text": "39399048"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Bulk Data Integration",
                    "text": "39399086"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39399043"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39399121"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39398953"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39398997"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39398952"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39398950"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
                    "text": "39399049"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Gateway",
                    "text": "39399127"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39213017"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39360371"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39398958"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39212120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail EFTLink",
                    "text": "39399094"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
                    "text": "39399051"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39323463"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39399111"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39399114"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39398864"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39298054"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39398863"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Development",
                    "text": "39370753"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
                    "text": "39398944"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39398988"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Instant Messaging Server",
                    "text": "39398943"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
                    "text": "39398949"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39198321"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39278469"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Analysis Tool (Apache Log4j)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Log4j)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via SYSLOG to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Log4j)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Log4j)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Log4j)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Extract Executable (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Log4j)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Application Framework accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager (Apache Log4j)).  Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via SYSLOG to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Development accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Process Management Suite accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Spatial Studio (component: Install issues (Apache Log4j)).  Supported versions that are affected are 23.2.1 and  24.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Spatial Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Spatial Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Management Cloud Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications BRM - Elastic Charging Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Apache Log4j)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Apache Log4j)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Apache Log4j)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications (component: XMPP Server (Apache Log4j)).   The supported version that is affected is 10.0.1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Instant Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications (component: NM Core (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Offline Mediation Controller accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Apache Log4j)).  Supported versions that are affected are 8.0.0, 7.5.0 and  7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Order and Service Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Management (Apache Log4j)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Performance Intelligence Center accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Log4j)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Apache Log4j)).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Log4j)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Log4j)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Policy Engine (Apache Log4j)).  Supported versions that are affected are 4.0.0-4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences Information Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Apache Log4j)).  Supported versions that are affected are 8.2.0.0-8.2.0.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Log4j)).  Supported versions that are affected are 5.0.0.0-5.0.9.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Master Person Index accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Bulk Data Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Log4j)).  Supported versions that are affected are 21.0.0-25.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Extract Tranform and Load product of Oracle Retail Applications (component: Mathematical Operators (Apache Log4j)).   The supported version that is affected is 13.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Extract Tranform and Load.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Extract Tranform and Load accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Integration Bus accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: EBS Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Price Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Service Backbone accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Apache Log4j)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Log4j)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Log4j)).  Supported versions that are affected are 21.12-21.12.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues (Apache Log4j)).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch Request (Apache Log4j)).  Supported versions that are affected are 8.0.0.7.0-8.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Service Catalog and Design accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Log4j)).   The supported version that is affected is 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Model Management and Governance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-10605V-21.12-21.12.17",
                    "P-1980V-14.1.2.1.0",
                    "P-4516V-7.7.0",
                    "P-13600V-23.2.1",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.4.1",
                    "P-5325V-12.2.1.4.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-9001V-17.0-26.5",
                    "P-14117V-25.2.200",
                    "P-10198V-12.2.1.4.0",
                    "P-5242V-12.2.1.4.0",
                    "P-2269V-15.0.0.0.0-15.2.0.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-14276V-8.1.2.7",
                    "P-14277V-25.2.200",
                    "P-11044V-10.5.0.2.0",
                    "P-2245V-4.5.0.2.0",
                    "P-10354V-23.12.0-23.12.16",
                    "P-10867V-16.0.3",
                    "P-5242V-14.1.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-2245V-25.10",
                    "P-12968V-16.0.3",
                    "P-10722V-19.0.1",
                    "P-2270V-7.5.0",
                    "P-9387V-3.6.1",
                    "P-4516V-7.6.0",
                    "P-13600V-24.2",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14119V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14392V-8.1.2.9",
                    "P-1980V-12.2.1.4.0",
                    "P-9742V-15.0.0.0.0",
                    "P-4516V-8.0.1",
                    "P-11513V-21.0.5-25.0.1",
                    "P-10867V-19.0.1",
                    "P-5680V-8.1.2.5.0",
                    "P-2545V-12.2.1.4.0",
                    "P-10198V-14.1.2.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-8495V-10.0.1.8.0",
                    "P-12968V-19.0.1",
                    "P-11044V-10.5.0.1.0",
                    "P-1824V-16.0.3",
                    "P-1807V-16.0.3",
                    "P-10354V-24.12.0-24.12.14",
                    "P-2283V-8.0.0.7.0-8.3.0.3.0",
                    "P-4647V-12.2.1.4.0",
                    "P-13784V-7.0.0.0.8",
                    "P-10354V-25.12.0-25.12.6",
                    "P-5325V-14.1.2.0.0",
                    "P-1807V-19.0.1",
                    "P-5680V-8.0.8.7.0",
                    "P-2245V-4.3.0.6.0",
                    "P-4516V-7.5.0",
                    "P-2545V-14.1.1.0.0",
                    "P-4516V-7.5.1",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14121V-25.2.200",
                    "P-2245V-26.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-10900V-15.0.0.0",
                    "P-2270V-8.0.0",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-8575V-5.0.0.0-5.0.9.6",
                    "P-5242V-14.1.2.0.0",
                    "P-2245V-4.5.0.0.0",
                    "P-1803V-13.2.8",
                    "P-9742V-15.1.0.0.0",
                    "P-9161V-8.2.0.0-8.2.0.7",
                    "P-10354V-21.12.0-21.12.17",
                    "P-13784V-7.0.0.1.7",
                    "P-5680V-8.0.7.9.0",
                    "P-9177V-4.0.0-4.0.2",
                    "P-8496V-8.1.0.0",
                    "P-4516V-7.8.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-9742V-15.0.1.0.0",
                    "P-11516V-21.0.0-25.0.0",
                    "P-2245V-4.4.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-2545V-15.1.1.0.0",
                    "P-2245V-25.4",
                    "P-14252V-25.2.0.0.0",
                    "P-2245V-4.5.0.1.1",
                    "P-10722V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-5242V-15.1.1.0.0",
                    "P-10354V-22.12.0-22.12.15",
                    "P-2245V-4.5.0.1.3",
                    "P-9008V-17.0-26.5",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-5757V-23.4-23.26.2",
                    "P-5760V-19.1.0.0.0-19.1.0.0.22",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21",
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5325V-14.1.2.0.0",
                        "P-1980V-14.1.2.1.0",
                        "P-2545V-12.2.1.4.0",
                        "P-10198V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-5242V-14.1.2.0.0",
                        "P-5325V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0",
                        "P-5242V-15.1.1.0.0",
                        "P-1980V-12.2.1.4.0",
                        "P-5242V-14.1.1.0.0",
                        "P-2545V-15.1.1.0.0",
                        "P-10198V-12.2.1.4.0",
                        "P-4647V-12.2.1.4.0",
                        "P-5242V-12.2.1.4.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5",
                        "P-9001V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10605V-21.12-21.12.17",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-13600V-23.2.1",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-13600V-24.2",
                        "P-5757V-21.3-21.21",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-4.4.0.0.0",
                        "P-13784V-25.4.0.0.3",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-25.4",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-2245V-26.4",
                        "P-2245V-25.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8495V-10.0.1.8.0",
                        "P-8496V-8.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU219"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2269V-15.0.0.0.0-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU228"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-8.0.0",
                        "P-2270V-7.5.0",
                        "P-2270V-7.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9161V-8.2.0.0-8.2.0.7",
                        "P-8575V-5.0.0.0-5.0.9.6",
                        "P-9177V-4.0.0-4.0.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU271"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-12968V-19.0.1",
                        "P-11516V-21.0.0-25.0.0",
                        "P-1803V-13.2.8",
                        "P-11513V-21.0.5-25.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1824V-16.0.3",
                        "P-12968V-16.0.3",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0.0.7.0-8.3.0.3.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14276V-8.1.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU283"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2283V-8.0.0.7.0-8.3.0.3.0",
                        "P-9008V-17.0-26.5",
                        "P-9001V-17.0-26.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34479",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39399100"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39399068"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Spatial Studio",
                    "text": "39398854"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Price Management",
                    "text": "39399108"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39398930"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
                    "text": "39398851"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39398935"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39398934"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39398932"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39198313"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39398938"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39398937"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39499467"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Extract Tranform and Load",
                    "text": "39399096"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399097"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
                    "text": "39742428"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39399132"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39398924"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39398928"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39398927"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39398926"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
                    "text": "39399048"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Bulk Data Integration",
                    "text": "39399086"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39399043"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39399121"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39398953"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39398997"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39398952"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39398950"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
                    "text": "39399049"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Gateway",
                    "text": "39399127"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39213017"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39360371"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39398958"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39212120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail EFTLink",
                    "text": "39399094"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483308"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
                    "text": "39399051"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39399111"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39399114"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39398864"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39298054"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39398863"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
                    "text": "39398944"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39398988"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Instant Messaging Server",
                    "text": "39398943"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
                    "text": "39398949"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39198321"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39278469"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Analysis Tool (Apache Log4j)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Log4j)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Log4j)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Log4j)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Log4j)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Application Framework accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Process Management Suite accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Spatial Studio (component: Install issues (Apache Log4j)).  Supported versions that are affected are 23.2.1 and  24.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Spatial Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Spatial Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Management Cloud Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications BRM - Elastic Charging Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Apache Log4j)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Apache Log4j)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Apache Log4j)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications (component: XMPP Server (Apache Log4j)).   The supported version that is affected is 10.0.1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Instant Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications (component: NM Core (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Offline Mediation Controller accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Apache Log4j)).  Supported versions that are affected are 8.0.0, 7.5.0 and  7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Order and Service Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Management (Apache Log4j)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Performance Intelligence Center accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Log4j)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Apache Log4j)).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Log4j)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Log4j)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Policy Engine (Apache Log4j)).  Supported versions that are affected are 4.0.0-4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences Information Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Apache Log4j)).  Supported versions that are affected are 8.2.0.0-8.2.0.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Log4j)).  Supported versions that are affected are 5.0.0.0-5.0.9.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Master Person Index accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Bulk Data Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Log4j)).  Supported versions that are affected are 21.0.0-25.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Extract Tranform and Load product of Oracle Retail Applications (component: Mathematical Operators (Apache Log4j)).   The supported version that is affected is 13.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Extract Tranform and Load.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Extract Tranform and Load accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Integration Bus accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: EBS Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Price Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Service Backbone accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Apache Log4j)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Log4j)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Log4j)).  Supported versions that are affected are 21.12-21.12.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues (Apache Log4j)).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Log4j)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of GoldenGate Stream Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch Request (Apache Log4j)).  Supported versions that are affected are 8.0.0.7.0-8.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Service Catalog and Design accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Log4j)).   The supported version that is affected is 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Model Management and Governance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-10605V-21.12-21.12.17",
                    "P-1980V-14.1.2.1.0",
                    "P-4516V-7.7.0",
                    "P-13600V-23.2.1",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.4.1",
                    "P-5325V-12.2.1.4.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-14117V-25.2.200",
                    "P-10198V-12.2.1.4.0",
                    "P-5242V-12.2.1.4.0",
                    "P-2269V-15.0.0.0.0-15.2.0.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-14276V-8.1.2.7",
                    "P-14277V-25.2.200",
                    "P-11044V-10.5.0.2.0",
                    "P-2245V-4.5.0.2.0",
                    "P-10354V-23.12.0-23.12.16",
                    "P-10867V-16.0.3",
                    "P-5242V-14.1.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-2245V-25.10",
                    "P-12968V-16.0.3",
                    "P-10722V-19.0.1",
                    "P-2270V-7.5.0",
                    "P-9387V-3.6.1",
                    "P-4516V-7.6.0",
                    "P-13600V-24.2",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14119V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14392V-8.1.2.9",
                    "P-1980V-12.2.1.4.0",
                    "P-9742V-15.0.0.0.0",
                    "P-4516V-8.0.1",
                    "P-11513V-21.0.5-25.0.1",
                    "P-10867V-19.0.1",
                    "P-5680V-8.1.2.5.0",
                    "P-2545V-12.2.1.4.0",
                    "P-10198V-14.1.2.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-8495V-10.0.1.8.0",
                    "P-12968V-19.0.1",
                    "P-11044V-10.5.0.1.0",
                    "P-1824V-16.0.3",
                    "P-1807V-16.0.3",
                    "P-10354V-24.12.0-24.12.14",
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-2283V-8.0.0.7.0-8.3.0.3.0",
                    "P-4647V-12.2.1.4.0",
                    "P-13784V-7.0.0.0.8",
                    "P-10354V-25.12.0-25.12.6",
                    "P-5325V-14.1.2.0.0",
                    "P-1807V-19.0.1",
                    "P-5680V-8.0.8.7.0",
                    "P-2245V-4.3.0.6.0",
                    "P-4516V-7.5.0",
                    "P-2545V-14.1.1.0.0",
                    "P-4516V-7.5.1",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14121V-25.2.200",
                    "P-2245V-26.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-10900V-15.0.0.0",
                    "P-2270V-8.0.0",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-8575V-5.0.0.0-5.0.9.6",
                    "P-5242V-14.1.2.0.0",
                    "P-2245V-4.5.0.0.0",
                    "P-1803V-13.2.8",
                    "P-9742V-15.1.0.0.0",
                    "P-9161V-8.2.0.0-8.2.0.7",
                    "P-10354V-21.12.0-21.12.17",
                    "P-13784V-7.0.0.1.7",
                    "P-5680V-8.0.7.9.0",
                    "P-9177V-4.0.0-4.0.2",
                    "P-8496V-8.1.0.0",
                    "P-4516V-7.8.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-9742V-15.0.1.0.0",
                    "P-11516V-21.0.0-25.0.0",
                    "P-2245V-4.4.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-2545V-15.1.1.0.0",
                    "P-2245V-25.4",
                    "P-14252V-25.2.0.0.0",
                    "P-2245V-4.5.0.1.1",
                    "P-10722V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-5242V-15.1.1.0.0",
                    "P-10354V-22.12.0-22.12.15",
                    "P-2245V-4.5.0.1.3",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-5760V-19.1.0.0.0-19.1.0.0.22",
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5325V-14.1.2.0.0",
                        "P-1980V-14.1.2.1.0",
                        "P-2545V-12.2.1.4.0",
                        "P-10198V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-5242V-14.1.2.0.0",
                        "P-5325V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0",
                        "P-5242V-15.1.1.0.0",
                        "P-1980V-12.2.1.4.0",
                        "P-5242V-14.1.1.0.0",
                        "P-2545V-15.1.1.0.0",
                        "P-10198V-12.2.1.4.0",
                        "P-4647V-12.2.1.4.0",
                        "P-5242V-12.2.1.4.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10605V-21.12-21.12.17",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-4.4.0.0.0",
                        "P-13784V-25.4.0.0.3",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-25.4",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-2245V-26.4",
                        "P-2245V-25.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                        "P-13600V-23.2.1",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-13600V-24.2",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8495V-10.0.1.8.0",
                        "P-8496V-8.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU219"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2269V-15.0.0.0.0-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU228"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-8.0.0",
                        "P-2270V-7.5.0",
                        "P-2270V-7.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9161V-8.2.0.0-8.2.0.7",
                        "P-8575V-5.0.0.0-5.0.9.6",
                        "P-9177V-4.0.0-4.0.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU271"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-12968V-19.0.1",
                        "P-11516V-21.0.0-25.0.0",
                        "P-1803V-13.2.8",
                        "P-11513V-21.0.5-25.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1824V-16.0.3",
                        "P-12968V-16.0.3",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0.0.7.0-8.3.0.3.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14276V-8.1.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU283"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34480",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "inline_mitigations_already_exist",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39399100"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39399068"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Spatial Studio",
                    "text": "39398854"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Price Management",
                    "text": "39399108"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39398930"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
                    "text": "39398851"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39398935"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39398934"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39398932"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39198313"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39398938"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39398937"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39499467"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Extract Tranform and Load",
                    "text": "39399096"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399097"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
                    "text": "39742428"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39399132"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39398924"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39398928"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39398927"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39398926"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39222930"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
                    "text": "39399048"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Bulk Data Integration",
                    "text": "39399086"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39399043"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39399121"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39398953"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39398997"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39398952"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39398950"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
                    "text": "39399049"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Gateway",
                    "text": "39399127"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39213017"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39360371"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39398958"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39212120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail EFTLink",
                    "text": "39399094"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483308"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
                    "text": "39399051"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39323463"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39399111"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39399114"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39398864"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39298054"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39398863"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
                    "text": "39398944"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39398988"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Instant Messaging Server",
                    "text": "39398943"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
                    "text": "39398949"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39198321"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39278469"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Analysis Tool (Apache Log4j)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Log4j)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Log4j)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (Apache Log4j)).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Log4j)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Extract Executable (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Log4j)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Application Framework accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Process Management Suite accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Spatial Studio (component: Install issues (Apache Log4j)).  Supported versions that are affected are 23.2.1 and  24.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Spatial Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Spatial Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Management Cloud Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications BRM - Elastic Charging Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Apache Log4j)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Apache Log4j)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Apache Log4j)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications (component: XMPP Server (Apache Log4j)).   The supported version that is affected is 10.0.1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Instant Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Messaging Server accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications (component: NM Core (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Offline Mediation Controller accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Apache Log4j)).  Supported versions that are affected are 8.0.0, 7.5.0 and  7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Order and Service Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Management (Apache Log4j)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Performance Intelligence Center accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Log4j)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Apache Log4j)).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Log4j)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Log4j)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Policy Engine (Apache Log4j)).  Supported versions that are affected are 4.0.0-4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences Information Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Apache Log4j)).  Supported versions that are affected are 8.2.0.0-8.2.0.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Log4j)).  Supported versions that are affected are 5.0.0.0-5.0.9.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Master Person Index accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Bulk Data Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Log4j)).  Supported versions that are affected are 21.0.0-25.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Extract Tranform and Load product of Oracle Retail Applications (component: Mathematical Operators (Apache Log4j)).   The supported version that is affected is 13.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Extract Tranform and Load.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Extract Tranform and Load accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Integration Bus accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: EBS Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Price Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Service Backbone accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Apache Log4j)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Log4j)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Log4j)).  Supported versions that are affected are 21.12-21.12.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues (Apache Log4j)).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Log4j)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of GoldenGate Stream Analytics accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch Request (Apache Log4j)).  Supported versions that are affected are 8.0.0.7.0-8.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Service Catalog and Design accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Log4j)).   The supported version that is affected is 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Model Management and Governance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-10605V-21.12-21.12.17",
                    "P-1980V-14.1.2.1.0",
                    "P-4516V-7.7.0",
                    "P-13600V-23.2.1",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.4.1",
                    "P-2025V-8.2.0.0.0",
                    "P-5325V-12.2.1.4.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-14117V-25.2.200",
                    "P-10198V-12.2.1.4.0",
                    "P-5242V-12.2.1.4.0",
                    "P-2269V-15.0.0.0.0-15.2.0.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-14276V-8.1.2.7",
                    "P-14277V-25.2.200",
                    "P-11044V-10.5.0.2.0",
                    "P-2245V-4.5.0.2.0",
                    "P-10354V-23.12.0-23.12.16",
                    "P-10867V-16.0.3",
                    "P-5242V-14.1.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-2245V-25.10",
                    "P-12968V-16.0.3",
                    "P-10722V-19.0.1",
                    "P-2270V-7.5.0",
                    "P-9387V-3.6.1",
                    "P-4516V-7.6.0",
                    "P-13600V-24.2",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14119V-25.2.200",
                    "P-14117V-25.2.100",
                    "P-14392V-8.1.2.9",
                    "P-1980V-12.2.1.4.0",
                    "P-9742V-15.0.0.0.0",
                    "P-4516V-8.0.1",
                    "P-11513V-21.0.5-25.0.1",
                    "P-10867V-19.0.1",
                    "P-5680V-8.1.2.5.0",
                    "P-2545V-12.2.1.4.0",
                    "P-10198V-14.1.2.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-8495V-10.0.1.8.0",
                    "P-12968V-19.0.1",
                    "P-11044V-10.5.0.1.0",
                    "P-1824V-16.0.3",
                    "P-1807V-16.0.3",
                    "P-10354V-24.12.0-24.12.14",
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-2283V-8.0.0.7.0-8.3.0.3.0",
                    "P-13784V-7.0.0.0.8",
                    "P-4647V-12.2.1.4.0",
                    "P-10354V-25.12.0-25.12.6",
                    "P-5325V-14.1.2.0.0",
                    "P-1807V-19.0.1",
                    "P-5680V-8.0.8.7.0",
                    "P-2245V-4.3.0.6.0",
                    "P-4516V-7.5.0",
                    "P-2545V-14.1.1.0.0",
                    "P-4516V-7.5.1",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14121V-25.2.200",
                    "P-2245V-26.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-10900V-15.0.0.0",
                    "P-2270V-8.0.0",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-8575V-5.0.0.0-5.0.9.6",
                    "P-5242V-14.1.2.0.0",
                    "P-2245V-4.5.0.0.0",
                    "P-1803V-13.2.8",
                    "P-9742V-15.1.0.0.0",
                    "P-9161V-8.2.0.0-8.2.0.7",
                    "P-10354V-21.12.0-21.12.17",
                    "P-13784V-7.0.0.1.7",
                    "P-2025V-26.01.0.0.0",
                    "P-5680V-8.0.7.9.0",
                    "P-9177V-4.0.0-4.0.2",
                    "P-8496V-8.1.0.0",
                    "P-4516V-7.8.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-9742V-15.0.1.0.0",
                    "P-11516V-21.0.0-25.0.0",
                    "P-2245V-4.4.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-2545V-15.1.1.0.0",
                    "P-2245V-25.4",
                    "P-14252V-25.2.0.0.0",
                    "P-2245V-4.5.0.1.1",
                    "P-10722V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-5242V-15.1.1.0.0",
                    "P-10354V-22.12.0-22.12.15",
                    "P-2245V-4.5.0.1.3",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-5757V-23.4-23.26.2",
                    "P-5760V-19.1.0.0.0-19.1.0.0.22",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21",
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5325V-14.1.2.0.0",
                        "P-1980V-14.1.2.1.0",
                        "P-2545V-12.2.1.4.0",
                        "P-10198V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-5242V-14.1.2.0.0",
                        "P-5325V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0",
                        "P-5242V-15.1.1.0.0",
                        "P-1980V-12.2.1.4.0",
                        "P-5242V-14.1.1.0.0",
                        "P-2545V-15.1.1.0.0",
                        "P-10198V-12.2.1.4.0",
                        "P-4647V-12.2.1.4.0",
                        "P-5242V-12.2.1.4.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10605V-21.12-21.12.17",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU217"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-13600V-23.2.1",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-13600V-24.2",
                        "P-5757V-21.3-21.21",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-4.4.0.0.0",
                        "P-13784V-25.4.0.0.3",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-25.4",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-2245V-26.4",
                        "P-2245V-25.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8495V-10.0.1.8.0",
                        "P-8496V-8.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU219"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2269V-15.0.0.0.0-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU228"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-8.0.0",
                        "P-2270V-7.5.0",
                        "P-2270V-7.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9161V-8.2.0.0-8.2.0.7",
                        "P-8575V-5.0.0.0-5.0.9.6",
                        "P-9177V-4.0.0-4.0.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU271"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-12968V-19.0.1",
                        "P-11516V-21.0.0-25.0.0",
                        "P-1803V-13.2.8",
                        "P-11513V-21.0.5-25.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1824V-16.0.3",
                        "P-12968V-16.0.3",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0.0.7.0-8.3.0.3.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14276V-8.1.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU283"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4647V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 4.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34481",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "inline_mitigations_already_exist",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39399100"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39399068"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Spatial Studio",
                    "text": "39398854"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Price Management",
                    "text": "39399108"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39398930"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
                    "text": "39398851"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39398935"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39398934"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39398932"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39198313"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39398938"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39398937"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39499467"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Extract Tranform and Load",
                    "text": "39399096"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39399097"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
                    "text": "39742428"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39399132"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39398924"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39398928"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39398927"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39398926"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
                    "text": "39399048"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Bulk Data Integration",
                    "text": "39399086"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
                    "text": "39399043"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39399121"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39398953"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39398997"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39398952"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39398950"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
                    "text": "39399049"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Gateway",
                    "text": "39399127"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39213017"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39360371"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39398958"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39212120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail EFTLink",
                    "text": "39399094"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483308"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
                    "text": "39399051"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39323463"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39399111"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39399114"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39398864"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39298054"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39398863"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
                    "text": "39398944"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39398988"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Instant Messaging Server",
                    "text": "39398943"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
                    "text": "39398949"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39278469"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39342032"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Log4j)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Log4j)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Log4j)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle GoldenGate (component: Extract Executable (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Log4j)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Application Framework accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Spatial Studio (component: Install issues (Apache Log4j)).  Supported versions that are affected are 23.2.1 and  24.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Spatial Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Spatial Studio accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Management Cloud Engine accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Apache Log4j)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Apache Log4j)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Apache Log4j)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Apache Log4j)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications (component: XMPP Server (Apache Log4j)).   The supported version that is affected is 10.0.1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Instant Messaging Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Messaging Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications (component: NM Core (Apache Log4j)).  Supported versions that are affected are 15.0.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Offline Mediation Controller accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Apache Log4j)).  Supported versions that are affected are 8.0.0, 7.5.0 and  7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Order and Service Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Management (Apache Log4j)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Performance Intelligence Center accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Log4j)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Policy Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Apache Log4j)).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Log4j)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Log4j)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Policy Engine (Apache Log4j)).  Supported versions that are affected are 4.0.0-4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences Information Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Apache Log4j)).  Supported versions that are affected are 8.2.0.0-8.2.0.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Data Repository accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Log4j)).  Supported versions that are affected are 5.0.0.0-5.0.9.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Master Person Index accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Apache Log4j)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Bulk Data Integration accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Log4j)).  Supported versions that are affected are 21.0.0-25.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Extract Tranform and Load product of Oracle Retail Applications (component: Mathematical Operators (Apache Log4j)).   The supported version that is affected is 13.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Extract Tranform and Load.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Extract Tranform and Load accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: EBS Integration (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Financial Integration accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Price Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Service Backbone accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Apache Log4j)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Log4j)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Testing Accelerator accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Log4j)).  Supported versions that are affected are 21.12-21.12.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues (Apache Log4j)).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Log4j)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of GoldenGate Stream Analytics accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch Request (Apache Log4j)).  Supported versions that are affected are 8.0.0.7.0-8.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Service Catalog and Design accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Log4j)).   The supported version that is affected is 8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-10605V-21.12-21.12.17",
                    "P-1980V-14.1.2.1.0",
                    "P-4516V-7.7.0",
                    "P-13600V-23.2.1",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.4.1",
                    "P-5325V-12.2.1.4.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-14117V-25.2.200",
                    "P-10198V-12.2.1.4.0",
                    "P-5242V-12.2.1.4.0",
                    "P-2269V-15.0.0.0.0-15.2.0.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-10722(Oracle Retail Financial Integration_EBS Integration)V-16.0.3",
                    "P-14276V-8.1.2.7",
                    "P-14119(Oracle Communications Cloud Native Core Unified Data Repository_Install)V-25.200",
                    "P-14277V-25.2.200",
                    "P-11044V-10.5.0.2.0",
                    "P-2245V-4.5.0.2.0",
                    "P-10354V-23.12.0-23.12.16",
                    "P-10867V-16.0.3",
                    "P-5242V-14.1.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-2245V-25.10",
                    "P-12968V-16.0.3",
                    "P-2270V-7.5.0",
                    "P-9387V-3.6.1",
                    "P-4516V-7.6.0",
                    "P-13600V-24.2",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14117V-25.2.100",
                    "P-14392V-8.1.2.9",
                    "P-1980V-12.2.1.4.0",
                    "P-9742V-15.0.0.0.0",
                    "P-4516V-8.0.1",
                    "P-11513V-21.0.5-25.0.1",
                    "P-10867V-19.0.1",
                    "P-5680V-8.1.2.5.0",
                    "P-2545V-12.2.1.4.0",
                    "P-10198V-14.1.2.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-8495V-10.0.1.8.0",
                    "P-12968V-19.0.1",
                    "P-11044V-10.5.0.1.0",
                    "P-10722(Oracle Retail Financial Integration_PeopleSoft Integration)V-16.0.3",
                    "P-1824V-16.0.3",
                    "P-1807V-16.0.3",
                    "P-10354V-24.12.0-24.12.14",
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-2283V-8.0.0.7.0-8.3.0.3.0",
                    "P-13784V-7.0.0.0.8",
                    "P-10354V-25.12.0-25.12.6",
                    "P-5325V-14.1.2.0.0",
                    "P-1807V-19.0.1",
                    "P-5680V-8.0.8.7.0",
                    "P-2245V-4.3.0.6.0",
                    "P-4516V-7.5.0",
                    "P-2545V-14.1.1.0.0",
                    "P-4516V-7.5.1",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14121V-25.2.200",
                    "P-2245V-26.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-10900V-15.0.0.0",
                    "P-2270V-8.0.0",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-8575V-5.0.0.0-5.0.9.6",
                    "P-5242V-14.1.2.0.0",
                    "P-2245V-4.5.0.0.0",
                    "P-1803V-13.2.8",
                    "P-9742V-15.1.0.0.0",
                    "P-9161V-8.2.0.0-8.2.0.7",
                    "P-10354V-21.12.0-21.12.17",
                    "P-13784V-7.0.0.1.7",
                    "P-5680V-8.0.7.9.0",
                    "P-9177V-4.0.0-4.0.2",
                    "P-8496V-8.1.0.0",
                    "P-10722(Oracle Retail Financial Integration_PeopleSoft Integration)V-19.0.1",
                    "P-14119(Oracle Communications Cloud Native Core Unified Data Repository_Install)V-25.2.200",
                    "P-4516V-7.8.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-9742V-15.0.1.0.0",
                    "P-11516V-21.0.0-25.0.0",
                    "P-2245V-4.4.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-2545V-15.1.1.0.0",
                    "P-2245V-25.4",
                    "P-14252V-25.2.0.0.0",
                    "P-2245V-4.5.0.1.1",
                    "P-13784V-25.4.0.0.3",
                    "P-5242V-15.1.1.0.0",
                    "P-10354V-22.12.0-22.12.15",
                    "P-10722(Oracle Retail Financial Integration_EBS Integration)V-19.0.1",
                    "P-2245V-4.5.0.1.3",
                    "P-14130V-25.2.200"
                ],
                "known_not_affected": [
                    "P-5757V-23.4-23.26.2",
                    "P-5760V-19.1.0.0.0-19.1.0.0.22",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21",
                    "P-5760V-23.4-23.26.1",
                    "P-5760V-21.3-21.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5325V-14.1.2.0.0",
                        "P-1980V-14.1.2.1.0",
                        "P-2545V-12.2.1.4.0",
                        "P-10198V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-5242V-14.1.2.0.0",
                        "P-5325V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0",
                        "P-5242V-15.1.1.0.0",
                        "P-1980V-12.2.1.4.0",
                        "P-5242V-14.1.1.0.0",
                        "P-2545V-15.1.1.0.0",
                        "P-10198V-12.2.1.4.0",
                        "P-5242V-12.2.1.4.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10605V-21.12-21.12.17",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-13600V-23.2.1",
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-13600V-24.2",
                        "P-5757V-21.3-21.21",
                        "P-5760V-21.3-21.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119(Oracle Communications Cloud Native Core Unified Data Repository_Install)V-25.200",
                        "P-14119(Oracle Communications Cloud Native Core Unified Data Repository_Install)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-4.4.0.0.0",
                        "P-13784V-25.4.0.0.3",
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-25.4",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-2245V-26.4",
                        "P-2245V-25.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8495V-10.0.1.8.0",
                        "P-8496V-8.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU219"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2269V-15.0.0.0.0-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU228"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-8.0.0",
                        "P-2270V-7.5.0",
                        "P-2270V-7.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9161V-8.2.0.0-8.2.0.7",
                        "P-8575V-5.0.0.0-5.0.9.6",
                        "P-9177V-4.0.0-4.0.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU271"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1807V-19.0.1",
                        "P-12968V-19.0.1",
                        "P-11516V-21.0.0-25.0.0",
                        "P-1803V-13.2.8",
                        "P-10722(Oracle Retail Financial Integration_PeopleSoft Integration)V-16.0.3",
                        "P-1824V-16.0.3",
                        "P-1807V-16.0.3",
                        "P-10722(Oracle Retail Financial Integration_EBS Integration)V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-11513V-21.0.5-25.0.1",
                        "P-10867V-19.0.1",
                        "P-10722(Oracle Retail Financial Integration_PeopleSoft Integration)V-19.0.1",
                        "P-12968V-16.0.3",
                        "P-10722(Oracle Retail Financial Integration_EBS Integration)V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0.0.7.0-8.3.0.3.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14276V-8.1.2.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU283"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5",
                        "P-10605V-21.12-21.12.17",
                        "P-5325V-14.1.2.0.0",
                        "P-1980V-14.1.2.1.0",
                        "P-4516V-7.7.0",
                        "P-1807V-19.0.1",
                        "P-5680V-8.0.8.7.0",
                        "P-13600V-23.2.1",
                        "P-9742V-15.2.0.0.0",
                        "P-2270V-7.4.1",
                        "P-2245V-4.3.0.6.0",
                        "P-5325V-12.2.1.4.0",
                        "P-4516V-7.5.0",
                        "P-2545V-14.1.1.0.0",
                        "P-4516V-7.5.1",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-14121V-25.2.200",
                        "P-14117V-25.2.200",
                        "P-10198V-12.2.1.4.0",
                        "P-5242V-12.2.1.4.0",
                        "P-2245V-26.4",
                        "P-2269V-15.0.0.0.0-15.2.0.0.0",
                        "P-2545V-14.1.2.0.0",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                        "P-10722(Oracle Retail Financial Integration_EBS Integration)V-16.0.3",
                        "P-14276V-8.1.2.7",
                        "P-14119(Oracle Communications Cloud Native Core Unified Data Repository_Install)V-25.200",
                        "P-14277V-25.2.200",
                        "P-14117V-25.1.200",
                        "P-10900V-15.0.0.0",
                        "P-11044V-10.5.0.2.0",
                        "P-2270V-8.0.0",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.2.0",
                        "P-8575V-5.0.0.0-5.0.9.6",
                        "P-5242V-14.1.2.0.0",
                        "P-2245V-4.5.0.0.0",
                        "P-1803V-13.2.8",
                        "P-9742V-15.1.0.0.0",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10867V-16.0.3",
                        "P-9161V-8.2.0.0-8.2.0.7",
                        "P-5242V-14.1.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-10354V-21.12.0-21.12.17",
                        "P-13784V-7.0.0.1.7",
                        "P-2245V-25.10",
                        "P-5680V-8.0.7.9.0",
                        "P-9177V-4.0.0-4.0.2",
                        "P-8496V-8.1.0.0",
                        "P-10722(Oracle Retail Financial Integration_PeopleSoft Integration)V-19.0.1",
                        "P-12968V-16.0.3",
                        "P-14119(Oracle Communications Cloud Native Core Unified Data Repository_Install)V-25.2.200",
                        "P-4516V-7.8.0",
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                        "P-2270V-7.5.0",
                        "P-9387V-3.6.1",
                        "P-9742V-15.0.1.0.0",
                        "P-11516V-21.0.0-25.0.0",
                        "P-2245V-4.4.0.0.0",
                        "P-4516V-7.6.0",
                        "P-13600V-24.2",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                        "P-14117V-25.2.100",
                        "P-14392V-8.1.2.9",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-1980V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-9742V-15.0.0.0.0",
                        "P-2245V-25.4",
                        "P-4516V-8.0.1",
                        "P-11513V-21.0.5-25.0.1",
                        "P-14252V-25.2.0.0.0",
                        "P-10867V-19.0.1",
                        "P-5680V-8.1.2.5.0",
                        "P-2545V-12.2.1.4.0",
                        "P-10198V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-8495V-10.0.1.8.0",
                        "P-2245V-4.5.0.1.1",
                        "P-12968V-19.0.1",
                        "P-11044V-10.5.0.1.0",
                        "P-10722(Oracle Retail Financial Integration_PeopleSoft Integration)V-16.0.3",
                        "P-1824V-16.0.3",
                        "P-1807V-16.0.3",
                        "P-13784V-25.4.0.0.3",
                        "P-5242V-15.1.1.0.0",
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10722(Oracle Retail Financial Integration_EBS Integration)V-19.0.1",
                        "P-2245V-4.5.0.1.3",
                        "P-13784V-7.0.0.0.8",
                        "P-10354V-25.12.0-25.12.6",
                        "P-14130V-25.2.200"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5760V-23.4-23.26.1",
                        "P-5760V-19.1.0.0.0-19.1.0.0.22",
                        "P-5760V-21.3-21.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34483",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39226171"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39261449"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39499517"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39261471"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39261450"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39261452"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Graph Server and Client",
                    "text": "39261466"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39261454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39261457"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Tomcat)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Management Cloud Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Tomcat)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Tomcat)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install issues (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200",
                    "P-10900V-15.0.0.0",
                    "P-4461V-9.3.6",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-9008V-17.0-26.5",
                    "P-11513V-21.0.5-25.0.1",
                    "P-14252V-25.2.0.0.0",
                    "P-14597V-6.1.1-7.0.0"
                ],
                "known_not_affected": [
                    "P-14069V-25.4.2",
                    "P-14069V-26.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.5-25.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34486",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39226171"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39261449"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39499517"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39261471"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39261450"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39261452"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Graph Server and Client",
                    "text": "39261466"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39261454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39261457"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Tomcat)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Management Cloud Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Tomcat)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Tomcat)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install issues (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200",
                    "P-10900V-15.0.0.0",
                    "P-4461V-9.3.6",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-9008V-17.0-26.5",
                    "P-11513V-21.0.5-25.0.1",
                    "P-14252V-25.2.0.0.0",
                    "P-14597V-6.1.1-7.0.0"
                ],
                "known_not_affected": [
                    "P-14069V-25.4.2",
                    "P-14069V-26.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.5-25.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34487",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39226171"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39261449"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39499517"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39261471"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39261450"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39261452"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Graph Server and Client",
                    "text": "39261466"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39261454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39261457"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Tomcat)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Management Cloud Engine accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Tomcat)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Tomcat)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Policy Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install issues (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200",
                    "P-10900V-15.0.0.0",
                    "P-4461V-9.3.6",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-9008V-17.0-26.5",
                    "P-11513V-21.0.5-25.0.1",
                    "P-14252V-25.2.0.0.0",
                    "P-14597V-6.1.1-7.0.0"
                ],
                "known_not_affected": [
                    "P-14069V-25.4.2",
                    "P-14069V-26.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.5-25.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14277V-25.2.200",
                        "P-10900V-15.0.0.0",
                        "P-4461V-9.3.6",
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                        "P-11513V-21.0.5-25.0.1",
                        "P-14252V-25.2.0.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34500",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39226171"
                },
                {
                    "system_name": "Oracle Bug ID of Management Cloud Engine",
                    "text": "39261449"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39499517"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39261471"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39261450"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39261452"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Graph Server and Client",
                    "text": "39261466"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39261454"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
                    "text": "39261457"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Tomcat)).   The supported version that is affected is 25.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Management Cloud Engine accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Tomcat)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Tomcat)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Policy Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install issues (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200",
                    "P-10900V-15.0.0.0",
                    "P-4461V-9.3.6",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-9008V-17.0-26.5",
                    "P-11513V-21.0.5-25.0.1",
                    "P-14252V-25.2.0.0.0",
                    "P-14597V-6.1.1-7.0.0"
                ],
                "known_not_affected": [
                    "P-14069V-25.4.2",
                    "P-14069V-26.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14252V-25.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU250"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10900V-15.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU242"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.5-25.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-17.0-26.5"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 4.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34513",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-34514",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-34515",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-34516",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-34517",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-34518",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-34519",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-34520",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1",
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34525",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39291876"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39291878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (AIOHTTP)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1",
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ]
        },
        {
            "cve": "CVE-2026-34757",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39197711"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Java SE (component: 2D (libpng)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-3505",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39229496"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39259769"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Bouncy Castle Java Library)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Bouncy Castle Java Library)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-14.1.2.0.0",
                    "P-2245V-4.5.0.1.3",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-2245V-4.5.0.1.1",
                    "P-2245V-4.5.0.2.0",
                    "P-2245V-25.4",
                    "P-2245V-26.4",
                    "P-2245V-4.3.0.6.0",
                    "P-2245V-4.5.0.0.0",
                    "P-2245V-25.10",
                    "P-2245V-4.4.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-25.4",
                        "P-2245V-26.4",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-25.10",
                        "P-2245V-4.4.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-25.4",
                        "P-2245V-26.4",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-25.10",
                        "P-2245V-4.4.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-35204",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39108251"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Helm)).  Supported versions that are affected are 22.3-26.4. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-35287",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
                    "text": "39443852"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4622V-13.3.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4622V-13.3.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU281"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4622V-13.3.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-35290",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
                    "text": "39443838"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4622V-13.3.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4622V-13.3.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU281"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4622V-13.3.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-35554",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "39276837"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39276859"
                },
                {
                    "system_name": "Oracle Bug ID of SQL Developer",
                    "text": "39276891"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
                    "text": "39276829"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
                    "text": "39276890"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39276892"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39276851"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39276862"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39276850"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39483209"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Origination",
                    "text": "39276844"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39276854"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Apache Kafka)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Data Quality accessible data as well as  unauthorized access to critical data or complete access to all Oracle Enterprise Data Quality accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache Kafka)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Corporate Lending Process Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Corporate Lending Process Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration (Apache Kafka)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Origination accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Origination accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Apache Kafka)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Apache Kafka)).  Supported versions that are affected are 25.1.200 and  25.2.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Service Communication Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Third Party (Apache Kafka)).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Third Party (Apache Kafka)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access (Apache Kafka)).  Supported versions that are affected are 21.12.0.0-21.12.21.8, 22.12.0.0-22.12.21.2, 23.12.0-23.12.19, 24.12.0-24.12.14 and  25.12.0-25.12.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portfolio Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the SQL Developer product of Oracle SQL Developer (component: Installation (Apache Kafka)).  Supported versions that are affected are 19.3-24.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all SQL Developer accessible data as well as  unauthorized access to critical data or complete access to all SQL Developer accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Third Party (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache Kafka)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-5680V-8.0.8.7.0",
                    "P-5579V-25.12.0-25.12.4",
                    "P-1875(SQL Developer_Installation)V-19.3-24.3",
                    "P-4516V-7.5.0",
                    "P-4516V-7.5.1",
                    "P-4516V-7.6.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14325V-14.6.0-14.8.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14117V-25.2.100",
                    "P-4516V-8.0.1",
                    "P-5579V-21.12.0.0-21.12.21.8",
                    "P-9464V-12.2.1.4.0",
                    "P-5680V-8.1.2.5.0",
                    "P-14117V-25.1.200",
                    "P-5579V-24.12.0-24.12.14",
                    "P-5579V-23.12.0-23.12.19",
                    "P-5579V-22.12.0.0-22.12.21.2",
                    "P-13701V-14.6.0-14.8.0",
                    "P-9464V-14.1.2.0.0",
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-5680V-8.0.7.9.0"
                ],
                "known_not_affected": [
                    "P-14547V-25.2.200",
                    "P-14547V-24.2.0.0.1",
                    "P-14547V-25.2.100",
                    "P-14547V-25.1.200",
                    "P-14547V-24.3.4",
                    "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9464V-12.2.1.4.0",
                        "P-9464V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14325V-14.6.0-14.8.0",
                        "P-13701V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5579V-25.12.0-25.12.4",
                        "P-5579V-24.12.0-24.12.14",
                        "P-5579V-23.12.0-23.12.19",
                        "P-5579V-22.12.0.0-22.12.21.2",
                        "P-5579V-21.12.0.0-21.12.21.8"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                        "P-1875(SQL Developer_Installation)V-19.3-24.3",
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14547V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4",
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-39892",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39343195"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39505689"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Visual Analyzer (Cryptography)).   The supported version that is affected is 8.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Cryptography)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-14974V-25.2.200",
                    "P-14974V-25.1.200"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU217"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-40179",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39056920"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Prometheus)).  Supported versions that are affected are 22.3-26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as  unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-40192",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_in_execute_path",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39509795"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39509794"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39509792"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39509791"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39488251"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Pillow)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Pillow)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Pillow)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: perf-info (Pillow)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                    "P-14277V-25.2.200",
                    "P-14130V-25.2.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14121V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                        "P-14277V-25.2.200",
                        "P-14130V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-40466",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39293312"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39293319"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
                    "text": "39293306"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Apache ActiveMQ)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Data Quality.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache ActiveMQ)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Third Party (Apache ActiveMQ)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5680V-8.1.2.5.0",
                    "P-5680V-8.0.7.9.0",
                    "P-9464V-12.2.1.4.0",
                    "P-9464V-14.1.2.0.0",
                    "P-5680V-8.0.8.7.0"
                ],
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9464V-12.2.1.4.0",
                        "P-9464V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-40973",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39464103"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464114"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39464104"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464106"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464099"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464102"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464098"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Boot)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Boot)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Boot)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Spring Boot)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Boot)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Spring Boot)).  Supported versions that are affected are 24.2.0.0.1 and  24.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Boot)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Boot)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14547V-24.2.0.0.1",
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-14277V-25.1.200",
                    "P-14547V-24.3.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14119V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14117V-25.1.200",
                    "P-14117V-25.2.100"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-40975",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39464103"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464114"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39464104"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464106"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464099"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464102"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464098"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Boot)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Boot)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Boot)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Spring Boot)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Boot)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Spring Boot)).  Supported versions that are affected are 24.2.0.0.1 and  24.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Boot)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Boot)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14547V-24.2.0.0.1",
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-14277V-25.1.200",
                    "P-14547V-24.3.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14119V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14117V-25.1.200",
                    "P-14117V-25.2.100"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-40976",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14117V-25.1.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39464103"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464114"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39464104"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464106"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464099"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464102"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464361"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464098"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Boot)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Boot)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Boot)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Spring Boot)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Boot)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Spring Boot)).  Supported versions that are affected are 24.2.0.0.1 and  24.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Boot)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Boot)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (libssh)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14547V-24.2.0.0.1",
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-14547V-24.3.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14119V-25.2.200",
                    "P-13784V-25.4.0.0.3"
                ],
                "known_not_affected": [
                    "P-14117V-25.2.100",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-14117V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14547V-24.2.0.0.1",
                        "P-14121V-25.1.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                        "P-14392V-8.1.3.1",
                        "P-14277V-25.1.200",
                        "P-14547V-24.3.4",
                        "P-14119V-25.2.200"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14117V-25.2.100",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14117V-25.1.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14117V-25.1.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-40977",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39464103"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39464114"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39464104"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39464106"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39464099"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39464101"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39464102"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39464098"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Boot)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Boot)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Boot)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install (Spring Boot)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Boot)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Spring Boot)).  Supported versions that are affected are 24.2.0.0.1 and  24.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Spring Boot)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Boot)).   The supported version that is affected is 8.1.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14547V-24.2.0.0.1",
                    "P-14121V-25.1.200",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-14392V-8.1.3.1",
                    "P-14277V-25.1.200",
                    "P-14547V-24.3.4",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14119V-25.2.200"
                ],
                "known_not_affected": [
                    "P-14117V-25.1.200",
                    "P-14117V-25.2.100"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41043",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39293312"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39293319"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
                    "text": "39293306"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Apache ActiveMQ)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Data Quality.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache ActiveMQ)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Third Party (Apache ActiveMQ)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5680V-8.1.2.5.0",
                    "P-5680V-8.0.7.9.0",
                    "P-9464V-12.2.1.4.0",
                    "P-9464V-14.1.2.0.0",
                    "P-5680V-8.0.8.7.0"
                ],
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9464V-12.2.1.4.0",
                        "P-9464V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41044",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "component_not_present",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39293312"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39293319"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
                    "text": "39293306"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Apache ActiveMQ)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Data Quality. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache ActiveMQ)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Third Party (Apache ActiveMQ)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5680V-8.1.2.5.0",
                    "P-5680V-8.0.7.9.0",
                    "P-9464V-12.2.1.4.0",
                    "P-9464V-14.1.2.0.0",
                    "P-5680V-8.0.8.7.0"
                ],
                "known_not_affected": [
                    "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9464V-12.2.1.4.0",
                        "P-9464V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0",
                        "P-9464V-12.2.1.4.0",
                        "P-9464V-14.1.2.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The software is not affected because the vulnerable component is not in the product.",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Third Party)V-19.1.0.0.0-19.1.0.0.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-4111",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687757"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (libarchive)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14868V-25.2.200"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Lian Owen"
                    ]
                }
            ],
            "cve": "CVE-2026-41254",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39352473"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D (Little CMS)).  Supported versions that are affected are Oracle Java SE: 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41409",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39354724"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
                    "text": "39339304"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39340263"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: BPM Foundation Services (Apache Mina)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Mina)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Mina)).   The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-12.2.1.4.0",
                    "P-5325V-12.2.1.4.0",
                    "P-5325V-14.1.2.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-5565V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5325V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-5565V-15.1.1.0.0",
                        "P-4647V-12.2.1.4.0",
                        "P-5325V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5325V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-5565V-15.1.1.0.0",
                        "P-4647V-12.2.1.4.0",
                        "P-5325V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41417",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-41635",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39354724"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39340263"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Mina)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Mina)).   The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-12.2.1.4.0",
                    "P-4647V-14.1.2.0.0",
                    "P-5565V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0",
                        "P-5565V-15.1.1.0.0",
                        "P-4647V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ]
        },
        {
            "cve": "CVE-2026-4176",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                },
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39400033"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39400034"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39400031"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39400053"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39400032"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39400041"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39400028"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39400029"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Perl)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (Perl)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Perl)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Perl)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: perf-info (Perl)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Perl)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Perl)).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                    "P-14277V-25.2.200",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-1870V-26.1.1.1.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-14130V-25.2.200",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-14117V-25.2.100",
                    "P-5(RDBMS)V-19.3-19.31",
                    "P-14117V-25.1.200",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-1870V-26.1.1.1.0",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.2.200",
                        "P-14277V-25.2.200",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                        "P-1870V-26.1.1.1.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-14130V-25.2.200",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_perf-info)V-25.1.203"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14117V-25.2.100",
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-14117V-25.1.200",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.1.200"
                    ]
                },
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41838",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41839",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41840",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41841",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41842",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41843",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41844",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41845",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41846",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41848",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41850",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41851",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41852",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41853",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41854",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ]
        },
        {
            "cve": "CVE-2026-41855",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39562528"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39562529"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
                    "text": "39562562"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39562563"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39562531"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39562532"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
                    "text": "39562565"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
                    "text": "39562533"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39562534"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39562568"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39562525"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39562526"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Spring Framework)).  Supported versions that are affected are 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Framework)).  Supported versions that are affected are 25.1.203 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Spring Framework)).  Supported versions that are affected are 25.1.200, 25.2.100 and  25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.1.200",
                    "P-10722V-19.0.1",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                    "P-14117V-25.1.200",
                    "P-1807V-19.0.1",
                    "P-9742V-15.2.0.0.0",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-10722V-16.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-14119V-25.2.200",
                    "P-1807V-16.0.3",
                    "P-13784V-25.4.0.0.3",
                    "P-14117V-25.2.100",
                    "P-14117V-25.2.200",
                    "P-10867V-16.0.3",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-14277V-25.1.200",
                    "P-10867V-19.0.1",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-14117V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU245"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10722V-19.0.1",
                        "P-10867V-16.0.3",
                        "P-1807V-19.0.1",
                        "P-10722V-16.0.3",
                        "P-10867V-19.0.1",
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14121V-25.1.200",
                        "P-10722V-19.0.1",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.1.203",
                        "P-14117V-25.1.200",
                        "P-1807V-19.0.1",
                        "P-9742V-15.2.0.0.0",
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                        "P-10722V-16.0.3",
                        "P-9742V-15.1.0.0.0",
                        "P-14119V-25.2.200",
                        "P-1807V-16.0.3",
                        "P-13784V-25.4.0.0.3",
                        "P-14117V-25.2.100",
                        "P-14117V-25.2.200",
                        "P-10867V-16.0.3",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_Configuration)V-25.2.200",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-14277V-25.1.200",
                        "P-10867V-19.0.1",
                        "P-14130V-25.2.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41989",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39399840"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39399848"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
                    "text": "39399841"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libgcrypt)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 6.7 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Install (libgcrypt)).   The supported version that is affected is 25.1.203. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Console executes to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 6.7 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libgcrypt)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 6.7 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14277V-25.2.200",
                    "P-14250V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14250V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU246"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14121V-25.2.200",
                        "P-14277V-25.2.200",
                        "P-14250V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41990",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39399840"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39399848"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
                    "text": "39399841"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libgcrypt)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Install (libgcrypt)).   The supported version that is affected is 25.1.203. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Console executes to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libgcrypt)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14121V-25.2.200",
                    "P-14277V-25.2.200",
                    "P-14250V-25.1.203"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14250V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU246"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-42198",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
                    "text": "39660290"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (PostgreSQL JDBC Driver)).  Supported versions that are affected are 25.1.203 and  25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via SQL to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14250V-25.1.203",
                    "P-14250V-25.2.201"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14250V-25.2.201",
                        "P-14250V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU246"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14250V-25.2.201",
                        "P-14250V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-42402",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39310232"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39366120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39446043"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Neethi)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Neethi)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  While the vulnerability is in Oracle Middleware Common Libraries and Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data as well as  unauthorized read access to a subset of Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Apache Neethi)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10354V-22.12.0-22.12.15",
                    "P-10354V-24.12.0-24.12.14",
                    "P-9348V-11.4.0",
                    "P-10354V-23.12.0-23.12.16",
                    "P-4647V-14.1.2.0.0",
                    "P-10354V-21.12.0-21.12.17",
                    "P-10354V-25.12.0-25.12.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-42403",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39366120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39446043"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Neethi)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  While the vulnerability is in Oracle Middleware Common Libraries and Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data as well as  unauthorized read access to a subset of Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Apache Neethi)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0",
                    "P-4647V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-42404",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39366120"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Neethi)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  While the vulnerability is in Oracle Middleware Common Libraries and Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data as well as  unauthorized read access to a subset of Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4647V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-42535",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-42536",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-42577",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39482563"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Netty)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  While the vulnerability is in GoldenGate Stream Analytics, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of GoldenGate Stream Analytics accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-13487V-14.5.0-14.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42578",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42579",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42580",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42581",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42582",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "39482563"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Netty)).   The supported version that is affected is 26.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  While the vulnerability is in GoldenGate Stream Analytics, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of GoldenGate Stream Analytics accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0",
                    "P-13487V-14.5.0-14.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42583",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42584",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42585",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42586",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42587",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
                    "text": "39397582"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS). CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-14119V-25.2.200",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14119V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU249"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14122V-24.2.5",
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-1870V-22.1.1.1.0",
                        "P-14974V-25.2.200",
                        "P-14547V-24.2.0",
                        "P-14974V-25.1.200",
                        "P-9742V-15.2.0.0.0",
                        "P-2270V-7.5.0",
                        "P-9742V-15.0.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-14547V-24.3.4",
                        "P-14119V-25.2.200",
                        "P-2283V-8.1.0.6.0",
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-11705V-23.2",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-11705V-23.1",
                        "P-2545V-15.1.1.0.0",
                        "P-9742V-15.0.0.0.0",
                        "P-11513V-24.0.2",
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                        "P-4516V-8.0.1",
                        "P-11513V-23.0.3",
                        "P-2545V-14.1.2.0.0",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                        "P-4623V-15.0.0.0.0",
                        "P-14121V-25.1.200",
                        "P-14277V-25.2.200",
                        "P-2545V-12.2.1.4.0",
                        "P-14547V-25.1.200",
                        "P-11513V-22.0.3",
                        "P-9742V-15.1.0.0.0",
                        "P-4623V-15.0.1.0.0",
                        "P-2283V-8.0.0.7.0",
                        "P-14130V-25.2.200"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 4.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-42764",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42766",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42767",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42768",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42769",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42770",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-42778",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Integrity",
                    "text": "39710966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39340263"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Mina)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications (component: Cartridges (Apache Mina)).  Supported versions that are affected are 7.3.6, 7.4.0, 7.5.0 and  8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4491V-7.4.0",
                    "P-4491V-7.5.0",
                    "P-4647V-14.1.2.0.0",
                    "P-4647V-12.2.1.4.0",
                    "P-4491V-7.3.6",
                    "P-4491V-8.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0",
                        "P-4647V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4491V-7.4.0",
                        "P-4491V-7.5.0",
                        "P-4491V-7.3.6",
                        "P-4491V-8.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU272"
                }
            ]
        },
        {
            "cve": "CVE-2026-42779",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Integrity",
                    "text": "39710966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39340263"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Mina)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications (component: Cartridges (Apache Mina)).  Supported versions that are affected are 7.3.6, 7.4.0, 7.5.0 and  8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-12.2.1.4.0",
                    "P-4491V-7.3.6",
                    "P-4491V-7.4.0",
                    "P-4491V-7.5.0",
                    "P-4647V-14.1.2.0.0",
                    "P-4491V-8.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0",
                        "P-4647V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4491V-7.4.0",
                        "P-4491V-7.5.0",
                        "P-4491V-7.3.6",
                        "P-4491V-8.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU272"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4491V-7.4.0",
                        "P-4491V-7.5.0",
                        "P-4491V-7.3.6",
                        "P-4491V-8.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-42945",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39443144"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (nginx)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.0",
                    "P-10761V-5.2",
                    "P-10761V-6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.0",
                        "P-10761V-5.2",
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU235"
                }
            ]
        },
        {
            "cve": "CVE-2026-43284",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "39529120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Performance Intelligence Center",
                    "text": "39384187"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
                    "text": "39377194"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "39370671"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (Loadable Kernel Module)).  Supported versions that are affected are 9.0.0.0.0-9.3.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Linux Kernel)).   The supported version that is affected is 15.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications User Data Repository executes to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications User Data Repository.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Performance Intelligence Center product of Oracle Communications (component: Security (Linux Kernel)).  Supported versions that are affected are 10.5.0.1.0 and  10.5.0.2.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Performance Intelligence Center executes to compromise Oracle Communications Performance Intelligence Center.  While the vulnerability is in Oracle Communications Performance Intelligence Center, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Performance Intelligence Center. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: IDIH Visualization (Linux Kernel)).  Supported versions that are affected are 9.1.0.0.0, 9.2.0.0.0, 9.3.0.0.0, 6.1.0.0.0,  6.2.0.0.0,  6.3.0.0.0 and  6.0.2.2.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  While the vulnerability is in Oracle Communications Diameter Signaling Router, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.2.0.0.0",
                    "P-10899V-6.1.0.0.0",
                    "P-10899V-9.1.0.0.0",
                    "P-11044V-10.5.0.2.0",
                    "P-10899V-9.3.0.0.0",
                    "P-10899V-6.3.0.0.0",
                    "P-11108V-15.0",
                    "P-10899V-9.0.0.0.0-9.3.0.0.0",
                    "P-11044V-10.5.0.1.0",
                    "P-10899V-6.0.2.2.0",
                    "P-10899V-6.2.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.2.0.0.0",
                        "P-10899V-6.1.0.0.0",
                        "P-10899V-9.1.0.0.0",
                        "P-10899V-9.3.0.0.0",
                        "P-10899V-6.3.0.0.0",
                        "P-10899V-9.0.0.0.0-9.3.0.0.0",
                        "P-10899V-6.0.2.2.0",
                        "P-10899V-6.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11108V-15.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU239"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11044V-10.5.0.2.0",
                        "P-11044V-10.5.0.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU247"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10899V-9.2.0.0.0",
                        "P-10899V-6.1.0.0.0",
                        "P-10899V-9.1.0.0.0",
                        "P-11044V-10.5.0.2.0",
                        "P-10899V-9.3.0.0.0",
                        "P-10899V-6.3.0.0.0",
                        "P-11044V-10.5.0.1.0",
                        "P-10899V-6.0.2.2.0",
                        "P-10899V-6.2.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-43500",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "39529120"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
                    "text": "39651881"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
                    "text": "39377194"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
                    "text": "39370671"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (Loadable Kernel Module)).  Supported versions that are affected are 9.0.0.0.0-9.3.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Linux Kernel)).   The supported version that is affected is 15.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications User Data Repository executes to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications User Data Repository. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: IDIH Visualization (Linux Kernel)).  Supported versions that are affected are 9.1.0.0.0, 9.2.0.0.0, 9.3.0.0.0, 6.1.0.0.0,  6.2.0.0.0,  6.3.0.0.0 and  6.0.2.2.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  While the vulnerability is in Oracle Communications Diameter Signaling Router, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Linux Kernel)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10899V-9.2.0.0.0",
                    "P-10899V-6.1.0.0.0",
                    "P-14125V-25.2.200",
                    "P-10899V-9.1.0.0.0",
                    "P-10899V-9.3.0.0.0",
                    "P-10899V-6.3.0.0.0",
                    "P-11108V-15.0",
                    "P-10899V-9.0.0.0.0-9.3.0.0.0",
                    "P-10899V-6.0.2.2.0",
                    "P-10899V-6.2.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10899V-9.2.0.0.0",
                        "P-10899V-6.1.0.0.0",
                        "P-10899V-9.1.0.0.0",
                        "P-10899V-9.3.0.0.0",
                        "P-10899V-6.3.0.0.0",
                        "P-10899V-9.0.0.0.0-9.3.0.0.0",
                        "P-10899V-6.0.2.2.0",
                        "P-10899V-6.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU232"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11108V-15.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU239"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14125V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU243"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14125V-25.2.200",
                        "P-11108V-15.0",
                        "P-10899V-9.0.0.0.0-9.3.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-43512",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39368782"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-43515",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39261471"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39368782"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 21.0.5-25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11513V-21.0.5-25.0.1"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-21.0.5-25.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-43951",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-44119",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-44185",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-44186",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-4424",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
                    "text": "39626022"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687757"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Console (libarchive)).  Supported versions that are affected are 25.1.203 and  25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Console accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (libarchive)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14250V-25.1.203",
                    "P-14868V-25.2.200",
                    "P-14250V-25.2.201"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14250V-25.2.201",
                        "P-14250V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU246"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14250V-25.2.201",
                        "P-14250V-25.1.203"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-44248",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
                    "text": "39166400"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
                    "text": "39428970"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39428981"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
                    "text": "39428971"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39428982"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
                    "text": "39429004"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
                    "text": "39428980"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39428978"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39428989"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39428968"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
                    "text": "39428979"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39398408"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
                    "text": "39428966"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39428974"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39428975"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39428972"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39428983"
                },
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39429005"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
                    "text": "39428973"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39428969"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Platform (Netty)).  Supported versions that are affected are 14.5.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security issues (Netty)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 24.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 25.1.200 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: CONFIG (Netty)).   The supported version that is affected is 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).  Supported versions that are affected are 25.1.203 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Netty)).  Supported versions that are affected are 24.2.0, 24.3.4, 25.1.200, 25.2.100 and  25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications (component: Common fns (Netty)).  Supported versions that are affected are 15.0.0.0.0 and  15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Patch (Netty)).  Supported versions that are affected are 8.0.0.7.0 and  8.1.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component (Netty)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.3, 23.0.3 and 24.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Third-party components (Netty)).   The supported version that is affected is 22.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14122V-24.2.5",
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201",
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-1870V-22.1.1.1.0",
                    "P-14974V-25.2.200",
                    "P-14547V-24.2.0",
                    "P-14974V-25.1.200",
                    "P-9742V-15.2.0.0.0",
                    "P-2270V-7.5.0",
                    "P-13487V-14.5.0-14.8.0",
                    "P-9742V-15.0.1.0.0",
                    "P-2545V-14.1.1.0.0",
                    "P-14547V-24.3.4",
                    "P-2283V-8.1.0.6.0",
                    "P-14547V-25.2.200",
                    "P-14547V-25.2.100",
                    "P-11705V-23.2",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                    "P-11705V-23.1",
                    "P-2545V-15.1.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-11513V-24.0.2",
                    "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0",
                    "P-4516V-8.0.1",
                    "P-11513V-23.0.3",
                    "P-2545V-14.1.2.0.0",
                    "P-14597V-6.1.1-7.0.0",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203",
                    "P-4623V-15.0.0.0.0",
                    "P-14121V-25.1.200",
                    "P-14277V-25.2.200",
                    "P-2545V-12.2.1.4.0",
                    "P-14547V-25.1.200",
                    "P-11513V-22.0.3",
                    "P-9742V-15.1.0.0.0",
                    "P-4623V-15.0.1.0.0",
                    "P-2283V-8.0.0.7.0",
                    "P-14130V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13487V-14.5.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14122V-24.2.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU240"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14974V-25.2.200",
                        "P-14974V-25.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU244"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_CONFIG)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14130V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU254"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.200",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.1.203"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU237"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-25.2.200",
                        "P-14547V-25.2.100",
                        "P-14547V-25.1.200",
                        "P-14547V-24.2.0",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4623V-15.0.1.0.0",
                        "P-4623V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU229"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2270V-7.5.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU226"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.1.0.6.0",
                        "P-2283V-8.0.0.7.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11513V-24.0.2",
                        "P-11513V-23.0.3",
                        "P-11513V-22.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-22.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13487V-14.5.0-14.8.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-44631",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-45445",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-45446",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-45447",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39548454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Database (OpenSSL) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Database (OpenSSL).  Successful attacks of this vulnerability can result in takeover of Database (OpenSSL).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Database)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Database)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ]
        },
        {
            "cve": "CVE-2026-46863",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39602113"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: MySQL Server).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU220"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46876",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
                    "text": "39443836"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4622V-13.3.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4622V-13.3.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU281"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4622V-13.3.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46917",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "37163878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46923",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Financials (International)",
                    "text": "39355546"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International).  While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-26V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-26V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-26V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46924",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
                    "text": "39443827"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4622V-13.3.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4622V-13.3.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU281"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4622V-13.3.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46936",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "37797437"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: DDL)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: DDL)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-8.0.0-8.0.47"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: DDL)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: DDL)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: DDL)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: DDL)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: DDL)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46941",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cost Management",
                    "text": "39384722"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management.  Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-569V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-569V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-569V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46943",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail EFTLink",
                    "text": "39350803"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin).  Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail EFTLink accessible data as well as  unauthorized access to critical data or complete access to all Oracle Retail EFTLink accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11516V-21.0.0-25.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11516V-21.0.0-25.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-11516V-21.0.0-25.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46948",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "38927730"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Security).  Supported versions that are affected are 2.4.0.1.0-2.4.0.1.32, 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.2.0-2.6.0.2.7 and  25.12.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as  unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2241V-2.5.0.2.0-2.5.0.2.11",
                    "P-2241V-2.5.0.1.0-2.5.0.1.17",
                    "P-2241V-2.6.0.2.0-2.6.0.2.7",
                    "P-2241V-2.4.0.1.0-2.4.0.1.32",
                    "P-2241V-25.12.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-2.5.0.1.0-2.5.0.1.17",
                        "P-2241V-25.12.0.0.0",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.7",
                        "P-2241V-2.4.0.1.0-2.4.0.1.32"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2241V-2.5.0.1.0-2.5.0.1.17",
                        "P-2241V-25.12.0.0.0",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.7",
                        "P-2241V-2.4.0.1.0-2.4.0.1.32"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46954",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Human Resources",
                    "text": "39392579"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Human Resources.  Successful attacks of this vulnerability can result in takeover of Oracle Human Resources. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-507V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-507V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-507V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46968",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "38423042"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data.  Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46975",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "38494116"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS.  While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 5.8 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-19.3-19.31",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46980",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "39456694"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile).  Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and  25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2241V-25.12.0.0.0-25.12.0.0.2",
                    "P-2241V-2.5.0.2.0-2.5.0.2.11",
                    "P-2241V-2.6.0.2.0-2.6.0.2.8",
                    "P-2241V-2.5.0.1.0-2.5.0.1.17",
                    "P-2241V-2.6.0.1.0-2.6.0.1.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-25.12.0.0.0-25.12.0.0.2",
                        "P-2241V-2.5.0.1.0-2.5.0.1.17",
                        "P-2241V-2.6.0.1.0-2.6.0.1.12",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.8"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2241V-25.12.0.0.0-25.12.0.0.2",
                        "P-2241V-2.5.0.1.0-2.5.0.1.17",
                        "P-2241V-2.6.0.1.0-2.6.0.1.12",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.8"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46981",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "39456725"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile).  Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and  25.12.0.0.0-25.12.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  While the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as  unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2241V-25.12.0.0.0-25.12.0.0.2",
                    "P-2241V-2.5.0.2.0-2.5.0.2.11",
                    "P-2241V-2.6.0.2.0-2.6.0.2.8",
                    "P-2241V-2.5.0.1.0-2.5.0.1.17",
                    "P-2241V-2.6.0.1.0-2.6.0.1.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-25.12.0.0.0-25.12.0.0.2",
                        "P-2241V-2.5.0.1.0-2.5.0.1.17",
                        "P-2241V-2.6.0.1.0-2.6.0.1.12",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.8"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2241V-25.12.0.0.0-25.12.0.0.2",
                        "P-2241V-2.5.0.1.0-2.5.0.1.17",
                        "P-2241V-2.6.0.1.0-2.6.0.1.12",
                        "P-2241V-2.5.0.2.0-2.5.0.2.11",
                        "P-2241V-2.6.0.2.0-2.6.0.2.8"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46982",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39452617"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).   The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1807V-14.1.3.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1807V-14.1.3.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1807V-14.1.3.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46983",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
                    "text": "39508510"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1807V-16.0.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1807V-16.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU198"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1807V-16.0.3"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Artur Bandura"
                    ]
                }
            ],
            "cve": "CVE-2026-46984",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39179125"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Artur Bandura"
                    ]
                }
            ],
            "cve": "CVE-2026-46985",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39179157"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Artur Bandura"
                    ]
                }
            ],
            "cve": "CVE-2026-46986",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39179198"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46987",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39344122"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46988",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39336398"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46989",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39343377"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46990",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39026715"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46991",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "38953406"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46992",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39344128"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46993",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39344125"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).  Supported versions that are affected are 13.5 and  24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46994",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39337839"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46995",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39336413"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46996",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39337842"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46997",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39340106"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46998",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39343373"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-46999",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39344126"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework).  Supported versions that are affected are 13.5 and  24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47000",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39336390"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework).   The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.5,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47001",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39337845"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Web Services Framework).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Jan Czerlunczakiewicz"
                    ],
                    "organization": "STM CYBER"
                }
            ],
            "cve": "CVE-2026-47002",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39235712"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47003",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39343375"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework).  Supported versions that are affected are 13.5 and  24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47004",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39336388"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47005",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39336399"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47006",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39336401"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU231"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47007",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
                    "text": "39427514"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center.  While the vulnerability is in Oracle Communications Pricing Design Center, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Pricing Design Center accessible data as well as  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9437V-15.2.0.0.0",
                    "P-9437V-15.0.0.0.0",
                    "P-9437V-15.0.1.0.0",
                    "P-9437V-15.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9437V-15.2.0.0.0",
                        "P-9437V-15.0.0.0.0",
                        "P-9437V-15.0.1.0.0",
                        "P-9437V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU223"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9437V-15.2.0.0.0",
                        "P-9437V-15.0.0.0.0",
                        "P-9437V-15.0.1.0.0",
                        "P-9437V-15.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Weiheng Qiu"
                    ],
                    "organization": "Vanderbilt University"
                }
            ],
            "cve": "CVE-2026-47008",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "38501299"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47009",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "38534958"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47010",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "38629286"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47011",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "38633557"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface).  Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.6,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47012",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "38657550"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47013",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "38722793"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: JavaFX).   The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47014",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Workbench",
                    "text": "38765433"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1597V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1597V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1597V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47015",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38788835"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).   The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47016",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "38843085"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe).  Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows physical access to compromise Siebel CRM Integration.  While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 1.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-17.0-26.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47017",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38850869"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47018",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "38881816"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47019",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "38892051"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47021",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "38922501"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47022",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
                    "text": "38126078"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security).   The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 3.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.3,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14015(GoldenGate Stream Analytics_Security)V-26.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47023",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "38924622"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47024",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38925560"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor).   The supported version that is affected is 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47026",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "38933729"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).  Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47027",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "38951266"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47028",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Document Management and Collaboration",
                    "text": "38892483"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Document Management and Collaboration accessible data as well as  unauthorized access to critical data or complete access to all Oracle Document Management and Collaboration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1314V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1314V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1314V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47030",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "38987788"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: JavaFX).   The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47031",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "38904586"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Bill Issues).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47032",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "38997166"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI).  Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 2.6 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-24.4-26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-24.4-26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.6,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-24.4-26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47033",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contracts Integration",
                    "text": "39390746"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration.  While the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Contracts Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-499V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-499V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-499V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47034",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39030200"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: JavaFX).   The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47035",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39030203"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: JavaFX).   The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47036",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Development",
                    "text": "39031156"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager).  Supported versions that are affected are 17.0-26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9001V-17.0-26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9001V-17.0-26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9001V-17.0-26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47037",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39274539"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).   The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Emad Al-Mousa"
                    ],
                    "organization": "Saudi Aramco's Upstream Digital Center (UDC)"
                }
            ],
            "cve": "CVE-2026-47038",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39052286"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-19.3-19.31",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47039",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39338556"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Java VM)V-19.3-19.31",
                    "P-5(Java VM)V-23.4.0-23.26.2",
                    "P-5(Java VM)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Java VM)V-23.4.0-23.26.2",
                        "P-5(Java VM)V-21.3-21.22",
                        "P-5(Java VM)V-19.3-19.31"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Java VM)V-23.4.0-23.26.2",
                        "P-5(Java VM)V-21.3-21.22",
                        "P-5(Java VM)V-19.3-19.31"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47040",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Net Services",
                    "text": "39234501"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Net Services component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Net Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-115V-21.3-21.22",
                    "P-115V-23.4.0-23.26.2",
                    "P-115V-19.3-19.31"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-115V-21.3-21.22",
                        "P-115V-19.3-19.31",
                        "P-115V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-115V-21.3-21.22",
                        "P-115V-19.3-19.31",
                        "P-115V-23.4.0-23.26.2"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Erichen"
                    ]
                }
            ],
            "cve": "CVE-2026-47041",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39499668"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.0,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Dhiraj Mishra"
                    ]
                }
            ],
            "cve": "CVE-2026-47043",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39277006"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Erichen"
                    ]
                }
            ],
            "cve": "CVE-2026-47044",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39499705"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Alexander Kornbrust"
                    ],
                    "organization": "Red Database Security"
                }
            ],
            "cve": "CVE-2026-47045",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39060101"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JDBC component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise JDBC.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of JDBC. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(JDBC)V-21.3-21.22",
                    "P-5(JDBC)V-23.4.0-23.26.2",
                    "P-5(JDBC)V-19.3-19.31"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(JDBC)V-21.3-21.22",
                        "P-5(JDBC)V-23.4.0-23.26.2",
                        "P-5(JDBC)V-19.3-19.31"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(JDBC)V-21.3-21.22",
                        "P-5(JDBC)V-23.4.0-23.26.2",
                        "P-5(JDBC)V-19.3-19.31"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47046",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39661066"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS as well as  unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Diego Palacios"
                    ]
                }
            ],
            "cve": "CVE-2026-47047",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39464931"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47048",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39062311"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).  Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47049",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39066356"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Hakim Bouhachni"
                    ],
                    "organization": "Calif.io"
                }
            ],
            "cve": "CVE-2026-47050",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39464955"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.8"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.8"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.8"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47051",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39081298"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47052",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39091376"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-8.0.0-8.0.47",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_InnoDB)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_InnoDB)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Joohyun Park"
                    ]
                }
            ],
            "cve": "CVE-2026-47053",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39465014"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.6 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Hazley Samsudin"
                    ]
                }
            ],
            "cve": "CVE-2026-47054",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39555545"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox.  Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Vmpr0be"
                    ]
                }
            ],
            "cve": "CVE-2026-47055",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39555705"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47056",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Data Integrator",
                    "text": "39114234"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2196V-14.1.2.0.0",
                    "P-2196V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "4ra1n, pyn3rd and unam4"
                    ]
                }
            ],
            "cve": "CVE-2026-47057",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39116690"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: Scripting).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and  11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-856V-11.0.31"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-856V-11.0.31"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-856V-11.0.31"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "4ra1n, pyn3rd and unam4"
                    ]
                }
            ],
            "cve": "CVE-2026-47058",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39116699"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: Scripting).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and  11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as  unauthorized access to critical data or complete access to all Oracle Java SE accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-856V-11.0.31"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-856V-11.0.31"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-856V-11.0.31"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "BBBBear"
                    ]
                }
            ],
            "cve": "CVE-2026-47059",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39127727"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Alexander Kornbrust"
                    ],
                    "organization": "Red Database Security"
                }
            ],
            "cve": "CVE-2026-47060",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39127997"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JDBC component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JDBC.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JDBC accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(JDBC)V-21.3-21.22",
                    "P-5(JDBC)V-23.4.0-23.26.2",
                    "P-5(JDBC)V-19.3-19.31"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(JDBC)V-21.3-21.22",
                        "P-5(JDBC)V-23.4.0-23.26.2",
                        "P-5(JDBC)V-19.3-19.31"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(JDBC)V-21.3-21.22",
                        "P-5(JDBC)V-23.4.0-23.26.2",
                        "P-5(JDBC)V-19.3-19.31"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Alexander Kornbrust"
                    ],
                    "organization": "Red Database Security"
                }
            ],
            "cve": "CVE-2026-47061",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39128024"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JDBC component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JDBC executes to compromise JDBC.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JDBC, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JDBC accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(JDBC)V-21.3-21.22",
                    "P-5(JDBC)V-23.4.0-23.26.2",
                    "P-5(JDBC)V-19.3-19.31"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(JDBC)V-21.3-21.22",
                        "P-5(JDBC)V-23.4.0-23.26.2",
                        "P-5(JDBC)V-19.3-19.31"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(JDBC)V-21.3-21.22",
                        "P-5(JDBC)V-23.4.0-23.26.2",
                        "P-5(JDBC)V-19.3-19.31"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Yukihiro Nakamura"
                    ]
                }
            ],
            "cve": "CVE-2026-47062",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39555717"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47063",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39132683"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "4ra1n, pyn3rd and unam4"
                    ]
                }
            ],
            "cve": "CVE-2026-47064",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39138426"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-4738",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39293442"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spatial and Graph (gdal) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31 and  23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via HTTPS to compromise Oracle Spatial and Graph (gdal).  Successful attacks of this vulnerability can result in takeover of Oracle Spatial and Graph (gdal). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-619(Oracle Spatial and Graph)V-19.3-19.31",
                    "P-619(Oracle Spatial and Graph)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-619(Oracle Spatial and Graph)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-619(Oracle Spatial and Graph)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-23.4.0-23.26.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-4800",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
                    "text": "39293057"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "39293038"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39293055"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
                    "text": "39293067"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
                    "text": "39293111"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
                    "text": "39293095"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39293052"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39293074"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39293118"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Graph Server and Client",
                    "text": "39293092"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Lodash)).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Lodash)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Lodash)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Lodash)).  Supported versions that are affected are 24.2.0.0.1, 24.3.4 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Lodash)).  Supported versions that are affected are 8.0.7.9.0, 8.0.8.7.0 and  8.1.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Lodash)).   The supported version that is affected is 8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install issues (Lodash)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Lodash)).  Supported versions that are affected are 23.1 and  23.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Cruise Shipboard Property Management (SPMS). CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Lodash)).  Supported versions that are affected are 7.0.0.0.8, 7.0.0.1.7 and  25.4.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Integration (Lodash)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5680V-8.1.2.5.0",
                    "P-14277V-25.2.200",
                    "P-14547V-25.1.200",
                    "P-5680V-8.0.8.7.0",
                    "P-13701V-14.6.0-14.8.0",
                    "P-14547V-24.3.4",
                    "P-13784V-25.4.0.0.3",
                    "P-10354V-22.12.0-22.12.15",
                    "P-10354V-24.12.0-24.12.14",
                    "P-10354V-23.12.0-23.12.16",
                    "P-14121V-25.2.200",
                    "P-14547V-24.2.0.0.1",
                    "P-14392V-8.1.2.9",
                    "P-11705V-23.2",
                    "P-11705V-23.1",
                    "P-10354V-21.12.0-21.12.17",
                    "P-13784V-7.0.0.0.8",
                    "P-13784V-7.0.0.1.7",
                    "P-5680V-8.0.7.9.0",
                    "P-10354V-25.12.0-25.12.6"
                ],
                "known_not_affected": [
                    "P-14069V-25.4.2",
                    "P-14069V-26.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13701V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14547V-24.2.0.0.1",
                        "P-14547V-25.1.200",
                        "P-14547V-24.3.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU252"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5680V-8.1.2.5.0",
                        "P-5680V-8.0.8.7.0",
                        "P-5680V-8.0.7.9.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU282"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.2.9"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11705V-23.2",
                        "P-11705V-23.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU257"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-13784V-25.4.0.0.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5680V-8.1.2.5.0",
                        "P-14277V-25.2.200",
                        "P-14547V-25.1.200",
                        "P-5680V-8.0.8.7.0",
                        "P-13701V-14.6.0-14.8.0",
                        "P-14547V-24.3.4",
                        "P-13784V-25.4.0.0.3",
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-14121V-25.2.200",
                        "P-14547V-24.2.0.0.1",
                        "P-14392V-8.1.2.9",
                        "P-11705V-23.2",
                        "P-11705V-23.1",
                        "P-10354V-21.12.0-21.12.17",
                        "P-13784V-7.0.0.0.8",
                        "P-13784V-7.0.0.1.7",
                        "P-5680V-8.0.7.9.0",
                        "P-10354V-25.12.0-25.12.6"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
                    "product_ids": [
                        "P-14069V-26.1.0",
                        "P-14069V-25.4.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-48913",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-49975",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39692054"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache HTTP Server)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                }
            ]
        },
        {
            "cve": "CVE-2026-5121",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39687757"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (libarchive)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14868V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ]
        },
        {
            "cve": "CVE-2026-54285",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle APEX",
                    "text": "39574632"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle APEX (component: Infrastructure (opentelemetry-js)).  Supported versions that are affected are 24.2 and  26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle APEX.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle APEX. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1348V-24.2",
                    "P-1348V-26.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1348V-24.2",
                        "P-1348V-26.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1348V-24.2",
                        "P-1348V-26.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-54512",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
                    "text": "39089386"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39667447"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39621052"
                },
                {
                    "system_name": "Oracle Bug ID of OPatch",
                    "text": "39611478"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39611474"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Third Party (jackson-core)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10 and  26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Fleet Patching and Provisioning (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Fleet Patching and Provisioning (jackson-databind).  Successful attacks of this vulnerability can result in takeover of Fleet Patching and Provisioning (jackson-databind).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the OPatch product of Oracle Global Lifecycle Management (component: Installer (jackson-databind)).  Supported versions that are affected are 12.2.0.1.16-12.2.0.1.51. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise OPatch.  Successful attacks of this vulnerability can result in takeover of OPatch.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (jackson-databind)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spatial and Graph (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.22. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via HTTP to compromise Oracle Spatial and Graph (jackson-databind).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Spatial and Graph (jackson-databind) accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-12753V-12.2.0.1.16-12.2.0.1.51",
                    "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-2245V-4.4.0.2.0-4.4.0.4.0",
                    "P-2245V-4.5.0.1.1",
                    "P-2245V-4.5.0.2.0",
                    "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                    "P-2245V-4.3.0.6.0",
                    "P-2245V-4.5.0.0.0",
                    "P-12738V-15.1.1.0.0",
                    "P-2245V-4.4.0.0.0",
                    "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2",
                    "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                    "P-12738V-14.1.2.0.0",
                    "P-2245V-4.5.0.1.3",
                    "P-12738V-14.1.2.1.0",
                    "P-2245V-25.4",
                    "P-2245V-26.4",
                    "P-2245V-25.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2245V-4.5.0.1.3",
                        "P-2245V-4.4.0.2.0-4.4.0.4.0",
                        "P-2245V-4.5.0.1.1",
                        "P-2245V-4.5.0.2.0",
                        "P-2245V-25.4",
                        "P-2245V-26.4",
                        "P-2245V-4.3.0.6.0",
                        "P-2245V-4.5.0.0.0",
                        "P-2245V-25.10",
                        "P-2245V-4.4.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU209"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                        "P-12753V-12.2.0.1.16-12.2.0.1.51",
                        "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                        "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-12738V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-54513",
            "flags": [
                {
                    "date": "2026-07-21T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39667447"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39621052"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39638098"
                },
                {
                    "system_name": "Oracle Bug ID of OPatch",
                    "text": "39611478"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39611474"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Fleet Patching and Provisioning (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Fleet Patching and Provisioning (jackson-databind).  Successful attacks of this vulnerability can result in takeover of Fleet Patching and Provisioning (jackson-databind).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the OPatch product of Oracle Global Lifecycle Management (component: Installer (jackson-databind)).  Supported versions that are affected are 12.2.0.1.16-12.2.0.1.51. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise OPatch.  Successful attacks of this vulnerability can result in takeover of OPatch.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (jackson-databind)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the RDBMS (jackson-databind) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spatial and Graph (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.22. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via HTTP to compromise Oracle Spatial and Graph (jackson-databind).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Spatial and Graph (jackson-databind) accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                    "P-12738V-14.1.2.0.0",
                    "P-12753V-12.2.0.1.16-12.2.0.1.51",
                    "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-12738V-14.1.2.1.0",
                    "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                    "P-12738V-15.1.1.0.0",
                    "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                ],
                "known_not_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                        "P-12753V-12.2.0.1.16-12.2.0.1.51",
                        "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.2"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-07-21T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-54514",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39667447"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39621052"
                },
                {
                    "system_name": "Oracle Bug ID of OPatch",
                    "text": "39611478"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39611474"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Fleet Patching and Provisioning (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Fleet Patching and Provisioning (jackson-databind).  Successful attacks of this vulnerability can result in takeover of Fleet Patching and Provisioning (jackson-databind).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the OPatch product of Oracle Global Lifecycle Management (component: Installer (jackson-databind)).  Supported versions that are affected are 12.2.0.1.16-12.2.0.1.51. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise OPatch.  Successful attacks of this vulnerability can result in takeover of OPatch.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (jackson-databind)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spatial and Graph (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.22. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via HTTP to compromise Oracle Spatial and Graph (jackson-databind).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Spatial and Graph (jackson-databind) accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                    "P-12738V-14.1.2.0.0",
                    "P-12753V-12.2.0.1.16-12.2.0.1.51",
                    "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-12738V-14.1.2.1.0",
                    "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                    "P-12738V-15.1.1.0.0",
                    "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                        "P-12753V-12.2.0.1.16-12.2.0.1.51",
                        "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                        "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ]
        },
        {
            "cve": "CVE-2026-54515",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39667447"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39621052"
                },
                {
                    "system_name": "Oracle Bug ID of OPatch",
                    "text": "39611478"
                },
                {
                    "system_name": "Oracle Bug ID of Primavera Unifier",
                    "text": "39419837"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39611474"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (jackson-core)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14 and  25.12.0-25.12.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Fleet Patching and Provisioning (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Fleet Patching and Provisioning (jackson-databind).  Successful attacks of this vulnerability can result in takeover of Fleet Patching and Provisioning (jackson-databind).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the OPatch product of Oracle Global Lifecycle Management (component: Installer (jackson-databind)).  Supported versions that are affected are 12.2.0.1.16-12.2.0.1.51. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise OPatch.  Successful attacks of this vulnerability can result in takeover of OPatch.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (jackson-databind)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spatial and Graph (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.22. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via HTTP to compromise Oracle Spatial and Graph (jackson-databind).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Spatial and Graph (jackson-databind) accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-12753V-12.2.0.1.16-12.2.0.1.51",
                    "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                    "P-12738V-15.1.1.0.0",
                    "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2",
                    "P-10354V-22.12.0-22.12.15",
                    "P-10354V-24.12.0-24.12.14",
                    "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                    "P-12738V-14.1.2.0.0",
                    "P-10354V-23.12.0-23.12.16",
                    "P-10354V-21.12.0-21.12.17",
                    "P-12738V-14.1.2.1.0",
                    "P-10354V-25.12.0-25.12.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU230"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                        "P-12753V-12.2.0.1.16-12.2.0.1.51",
                        "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                        "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10354V-22.12.0-22.12.15",
                        "P-10354V-24.12.0-24.12.14",
                        "P-10354V-23.12.0-23.12.16",
                        "P-10354V-21.12.0-21.12.17",
                        "P-10354V-25.12.0-25.12.6"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-619(Oracle Spatial and Graph)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-54516",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39667447"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39621052"
                },
                {
                    "system_name": "Oracle Bug ID of OPatch",
                    "text": "39611478"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39611474"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Fleet Patching and Provisioning (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Fleet Patching and Provisioning (jackson-databind).  Successful attacks of this vulnerability can result in takeover of Fleet Patching and Provisioning (jackson-databind).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the OPatch product of Oracle Global Lifecycle Management (component: Installer (jackson-databind)).  Supported versions that are affected are 12.2.0.1.16-12.2.0.1.51. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise OPatch.  Successful attacks of this vulnerability can result in takeover of OPatch.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (jackson-databind)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spatial and Graph (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.22. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via HTTP to compromise Oracle Spatial and Graph (jackson-databind).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Spatial and Graph (jackson-databind) accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                    "P-12738V-14.1.2.0.0",
                    "P-12753V-12.2.0.1.16-12.2.0.1.51",
                    "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-12738V-14.1.2.1.0",
                    "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                    "P-12738V-15.1.1.0.0",
                    "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                        "P-12753V-12.2.0.1.16-12.2.0.1.51",
                        "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                        "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ]
        },
        {
            "cve": "CVE-2026-54517",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39667447"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39621052"
                },
                {
                    "system_name": "Oracle Bug ID of OPatch",
                    "text": "39611478"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39611474"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Fleet Patching and Provisioning (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Fleet Patching and Provisioning (jackson-databind).  Successful attacks of this vulnerability can result in takeover of Fleet Patching and Provisioning (jackson-databind).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the OPatch product of Oracle Global Lifecycle Management (component: Installer (jackson-databind)).  Supported versions that are affected are 12.2.0.1.16-12.2.0.1.51. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise OPatch.  Successful attacks of this vulnerability can result in takeover of OPatch.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (jackson-databind)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spatial and Graph (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.22. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via HTTP to compromise Oracle Spatial and Graph (jackson-databind).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Spatial and Graph (jackson-databind) accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                    "P-12738V-14.1.2.0.0",
                    "P-12753V-12.2.0.1.16-12.2.0.1.51",
                    "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-12738V-14.1.2.1.0",
                    "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                    "P-12738V-15.1.1.0.0",
                    "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                        "P-12753V-12.2.0.1.16-12.2.0.1.51",
                        "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                        "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ]
        },
        {
            "cve": "CVE-2026-54518",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39667447"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39621052"
                },
                {
                    "system_name": "Oracle Bug ID of OPatch",
                    "text": "39611478"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39611474"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39693889"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Fleet Patching and Provisioning (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Fleet Patching and Provisioning (jackson-databind).  Successful attacks of this vulnerability can result in takeover of Fleet Patching and Provisioning (jackson-databind). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the OPatch product of Oracle Global Lifecycle Management (component: Installer (jackson-databind)).  Supported versions that are affected are 12.2.0.1.16-12.2.0.1.51. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise OPatch.  Successful attacks of this vulnerability can result in takeover of OPatch. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (jackson-databind)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spatial and Graph (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.22. Easily exploitable vulnerability allows low privileged attacker having None privilege with network access via HTTP to compromise Oracle Spatial and Graph (jackson-databind).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Spatial and Graph (jackson-databind) accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (jackson-core)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-12753V-12.2.0.1.16-12.2.0.1.51",
                    "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                    "P-12738V-15.1.1.0.0",
                    "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0",
                    "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                    "P-12738V-14.1.2.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                    "P-12738V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                        "P-12753V-12.2.0.1.16-12.2.0.1.51",
                        "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                        "P-619(Oracle Spatial and Graph)V-21.3-21.22",
                        "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Fleet Patching and Provisioning)V-21.3-21.22",
                        "P-5(Fleet Patching and Provisioning)V-19.3-19.31",
                        "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.2"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0",
                        "P-12753V-12.2.0.1.16-12.2.0.1.51",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.2.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-5588",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39229496"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
                    "text": "39696091"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
                    "text": "39229488"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Bouncy Castle Java Library)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle Management NextGen OUI Framework accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Bouncy Castle Java Library)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (Bouncy Castle Java Library)).   The supported version that is affected is 25.2.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Certificate Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-12738V-14.1.2.0.0",
                    "P-14868V-25.2.200",
                    "P-4647V-14.1.2.0.0",
                    "P-12738V-12.2.1.4.0",
                    "P-12738V-14.1.1.0.0",
                    "P-12738V-14.1.2.1.0",
                    "P-12738V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12738V-14.1.2.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14868V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU253"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-12738V-14.1.2.0.0",
                        "P-14868V-25.2.200",
                        "P-12738V-12.2.1.4.0",
                        "P-12738V-14.1.1.0.0",
                        "P-12738V-14.1.2.1.0",
                        "P-12738V-15.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-5598",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39229496"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39596053"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Bouncy Castle Java Library)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Bouncy Castle Java Library)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-12.2.1.4.0",
                    "P-4647V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.2.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4647V-14.1.2.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-5795",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
                    "text": "39311778"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
                    "text": "39311789"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
                    "text": "39311777"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
                    "text": "39311776"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Eclipse Jetty)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (Eclipse Jetty)).   The supported version that is affected is 25.2.201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Eclipse Jetty)).   The supported version that is affected is 25.2.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Eclipse Jetty)).   The supported version that is affected is 8.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                    "P-14392V-8.1.3.0",
                    "P-14121V-25.2.200",
                    "P-14277V-25.2.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14121V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU238"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU241"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14277V-25.2.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU288"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14392V-8.1.3.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU255"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14121V-25.2.200",
                        "P-14277V-25.2.200",
                        "P-14118(Oracle Communications Cloud Native Core Network Repository Function_Configuration)V-25.2.201",
                        "P-14392V-8.1.3.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60143",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Workflow",
                    "text": "39383842"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as  unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-174V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-174V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-174V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60144",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Workflow",
                    "text": "39383857"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-174V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-174V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.6,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-174V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Weiheng Qiu"
                    ],
                    "organization": "Vanderbilt University"
                }
            ],
            "cve": "CVE-2026-60145",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39179197"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Adam Kues"
                    ],
                    "organization": "Assetnote Security Research Team"
                },
                {
                    "names": [
                        "Dylan Pindur"
                    ],
                    "organization": "Assetnote Security Research Team"
                },
                {
                    "names": [
                        "Shubham Shah"
                    ],
                    "organization": "Assetnote Security Research Team"
                }
            ],
            "cve": "CVE-2026-60146",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39179665"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as  unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "1seal"
                    ]
                },
                {
                    "names": [
                        "tonghuaroot"
                    ]
                }
            ],
            "cve": "CVE-2026-60147",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39081549"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.0.11",
                    "P-856V-8u491-perf",
                    "P-856V-8u491",
                    "P-13497V-21.3.18",
                    "P-856V-26.0.1",
                    "P-856V-21.0.11",
                    "P-856V-25.0.3",
                    "P-856V-17.0.19",
                    "P-856V-11.0.31",
                    "P-13497V-17.0.19"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-21.0.11",
                        "P-856V-8u491-perf",
                        "P-856V-8u491",
                        "P-13497V-21.3.18",
                        "P-856V-26.0.1",
                        "P-856V-21.0.11",
                        "P-856V-25.0.3",
                        "P-856V-17.0.19",
                        "P-856V-11.0.31",
                        "P-13497V-17.0.19"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60149",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Workflow",
                    "text": "39383894"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Workflow as well as  unauthorized update, insert or delete access to some of Oracle Workflow accessible data and  unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-174V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-174V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-174V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Tr?n Th�i D??ng"
                    ],
                    "organization": "CyStack"
                }
            ],
            "cve": "CVE-2026-60150",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39558369"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60151",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39097245"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60152",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39208448"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61",
                    "P-5085V-8.62"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61",
                        "P-5085V-8.62"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60153",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39213512"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60154",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39217822"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as  unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "crixer (pwning_me) working with TrendAI Zero Day Initiative"
                    ]
                }
            ],
            "cve": "CVE-2026-60155",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39638781"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60156",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle APEX",
                    "text": "39233225"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle APEX (component: General).  Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle APEX.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle APEX accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1348V-24.1",
                    "P-1348V-24.2",
                    "P-1348V-26.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1348V-24.2",
                        "P-1348V-26.1",
                        "P-1348V-24.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1348V-24.2",
                        "P-1348V-26.1",
                        "P-1348V-24.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60157",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39233374"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Service Manager).  Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and  23.4-23.26.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1.0.0",
                    "P-5757V-19.1.0.0.0-19.29.0.0",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1.0.0",
                        "P-5757V-19.1.0.0.0-19.29.0.0",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1.0.0",
                        "P-5757V-19.1.0.0.0-19.29.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Vmpr0be"
                    ]
                }
            ],
            "cve": "CVE-2026-60158",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39653130"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Xiaobye (xiaobye_tw)"
                    ],
                    "organization": "DEVCORE Research Team working with TrendAI Zero Day Initiative"
                }
            ],
            "cve": "CVE-2026-60159",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39699155"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Hhy"
                    ]
                }
            ],
            "cve": "CVE-2026-60160",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39699209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Giovanni Vignone"
                    ],
                    "organization": "Octane Security"
                },
                {
                    "names": [
                        "Paolo Gentry"
                    ],
                    "organization": "Octane Security"
                },
                {
                    "names": [
                        "Robert van Eijk"
                    ],
                    "organization": "Octane Security"
                },
                {
                    "names": [
                        "Shubham Antil"
                    ],
                    "organization": "Octane Security"
                }
            ],
            "cve": "CVE-2026-60161",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39699313"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Xiaobye (xiaobye_tw)"
                    ],
                    "organization": "DEVCORE Research Team working with TrendAI Zero Day Initiative"
                }
            ],
            "cve": "CVE-2026-60162",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39733822"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU279"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.12"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Asim Viladi Oglu Manizada"
                    ]
                }
            ],
            "cve": "CVE-2026-60163",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39234600"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60164",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39235393"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: JavaFX).   The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60165",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cost Management",
                    "text": "39491702"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Enterprise Command Center).   The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-569V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-569V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-569V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60166",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39235506"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: JavaFX).   The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Jimi Sebree"
                    ],
                    "organization": "Horizon3.ai"
                }
            ],
            "cve": "CVE-2026-60167",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Simphony",
                    "text": "39235616"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).  Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and  19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11594V-19.10",
                    "P-11594V-19.8-19.8.5",
                    "P-11594V-19.9-19.9.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11594V-19.10",
                        "P-11594V-19.8-19.8.5",
                        "P-11594V-19.9-19.9.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU256"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-11594V-19.10",
                        "P-11594V-19.8-19.8.5",
                        "P-11594V-19.9-19.9.3"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Jimi Sebree"
                    ],
                    "organization": "Horizon3.ai"
                }
            ],
            "cve": "CVE-2026-60168",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Simphony",
                    "text": "39235623"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).  Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and  19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11594V-19.10",
                    "P-11594V-19.8-19.8.5",
                    "P-11594V-19.9-19.9.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11594V-19.10",
                        "P-11594V-19.8-19.8.5",
                        "P-11594V-19.9-19.9.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU256"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-11594V-19.10",
                        "P-11594V-19.8-19.8.5",
                        "P-11594V-19.9-19.9.3"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Jimi Sebree"
                    ],
                    "organization": "Horizon3.ai"
                }
            ],
            "cve": "CVE-2026-60169",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Simphony",
                    "text": "39235672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).  Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and  19.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11594V-19.10",
                    "P-11594V-19.8-19.8.5",
                    "P-11594V-19.9-19.9.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11594V-19.10",
                        "P-11594V-19.8-19.8.5",
                        "P-11594V-19.9-19.9.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU256"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-11594V-19.10",
                        "P-11594V-19.8-19.8.5",
                        "P-11594V-19.9-19.9.3"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Jimi Sebree"
                    ],
                    "organization": "Horizon3.ai"
                }
            ],
            "cve": "CVE-2026-60170",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hospitality Simphony",
                    "text": "39235685"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).  Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and  19.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-11594V-19.10",
                    "P-11594V-19.8-19.8.5",
                    "P-11594V-19.9-19.9.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-11594V-19.10",
                        "P-11594V-19.8-19.8.5",
                        "P-11594V-19.9-19.9.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU256"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-11594V-19.10",
                        "P-11594V-19.8-19.8.5",
                        "P-11594V-19.9-19.9.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60171",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Cluster",
                    "text": "39238139"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.47. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster_Server: Optimizer)V-8.0.0-8.0.47"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60172",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39242592"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform).  Supported versions that are affected are 26.0.0, 26.1.0 and  26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14634V-26.2.0",
                    "P-14634V-26.1.0",
                    "P-14634V-26.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.2.0",
                        "P-14634V-26.1.0",
                        "P-14634V-26.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14634V-26.2.0",
                        "P-14634V-26.1.0",
                        "P-14634V-26.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60173",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "38559372"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU217"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60174",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39243027"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60175",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39290842"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31, 21.3-21.22 and  23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-19.3-19.31",
                    "P-5(RDBMS)V-21.3-21.22"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2",
                        "P-5(RDBMS)V-21.3-21.22"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60176",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payments",
                    "text": "39244724"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Payments accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Payments. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-378V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-378V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-378V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60177",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39245805"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60178",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39245844"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60179",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39247067"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/C++)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/C++)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/C++)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60180",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39247162"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).  Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/C++)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/C++)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/C++)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60181",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39248605"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Configurator)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Configurator)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Configurator)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Configurator)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Configurator)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Configurator)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60182",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39252316"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60183",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39253040"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Clone Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Clone Plugin)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Dennis Tighe"
                    ]
                }
            ],
            "cve": "CVE-2026-60184",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39253359"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Dennis Tighe"
                    ]
                },
                {
                    "names": [
                        "Omkhar Arasaratnam"
                    ],
                    "organization": "Linkedin"
                }
            ],
            "cve": "CVE-2026-60185",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39253383"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60186",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39253416"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication Plugin)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60187",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39253491"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60188",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39254867"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60189",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39254885"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60190",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39254896"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 2.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60191",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39254914"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60192",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39255116"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60193",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39255163"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Weiheng Qiu"
                    ],
                    "organization": "Vanderbilt University"
                }
            ],
            "cve": "CVE-2026-60194",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39255734"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Weiheng Qiu"
                    ],
                    "organization": "Vanderbilt University"
                }
            ],
            "cve": "CVE-2026-60195",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39255759"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON Duality)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60196",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263597"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle WebLogic Server executes to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60197",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263619"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60198",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263669"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60199",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263678"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60200",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263680"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60201",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263703"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60202",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263706"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60203",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263733"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60204",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263739"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60205",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263769"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60206",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263785"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60207",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263787"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60208",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263792"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60209",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263806"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60210",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263808"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60211",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263810"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60212",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263811"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60213",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263812"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as  unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60214",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263813"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60215",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263814"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60216",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263815"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60217",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263816"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60218",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263817"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60219",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263818"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60220",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263819"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60221",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263820"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60222",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263821"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60223",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263822"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60224",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263823"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60225",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263824"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60226",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263825"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60227",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263826"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60228",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263827"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60229",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263828"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60230",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263829"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60231",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263831"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60232",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263832"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60233",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263833"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).   The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60234",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263834"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60235",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263835"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).   The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as  unauthorized update, insert or delete access to some of Oracle Coherence accessible data and  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60236",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263836"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60237",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263837"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60238",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263839"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60239",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263840"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60240",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263841"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60241",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263844"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60242",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263846"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60243",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263847"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60244",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263848"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60245",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263849"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60246",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263850"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60247",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263851"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60248",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263852"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60249",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263854"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60250",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263855"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60251",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263856"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60252",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263857"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60253",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263858"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60254",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60255",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263860"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as  unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60256",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263861"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60257",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263862"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60258",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263863"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60259",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263864"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60260",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263865"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60261",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263867"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60262",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263869"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60263",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263870"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60264",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263872"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60265",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263873"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.0,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60266",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263876"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60267",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60268",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263881"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60269",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263882"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60270",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263883"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as  unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60271",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263884"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60272",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263885"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60273",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263886"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60274",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263887"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60275",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263888"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60276",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263890"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60277",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263891"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60278",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263892"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-14.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60279",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263895"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60280",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263897"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60281",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263898"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60282",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263899"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60283",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263900"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60284",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263901"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as  unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60285",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263902"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60286",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263903"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60287",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263904"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60288",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263905"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60289",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263917"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60290",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39263918"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60291",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39264391"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60292",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39264395"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-14.1.1.0.0",
                    "P-5242V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60293",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39264396"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60294",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39264398"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60295",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264400"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60296",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264401"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60297",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264402"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60298",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264403"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60299",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264404"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Trung Nguyen"
                    ],
                    "organization": "CyStack"
                }
            ],
            "cve": "CVE-2026-60300",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264406"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60301",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264409"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60302",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264410"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60303",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264413"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60304",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264414"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60305",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264415"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60306",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264419"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60307",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264420"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60308",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264423"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60309",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39264425"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60310",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Performance Management",
                    "text": "39265425"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Performance Management accessible data as well as  unauthorized read access to a subset of Oracle Performance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4425V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4425V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4425V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Haogang Mao"
                    ],
                    "organization": "SKLCCSE Lab at Beihang University"
                }
            ],
            "cve": "CVE-2026-60311",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39679910"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 9.0.0-9.7.1;  MySQL Cluster: 9.0.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.0.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.0.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.0.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.0.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.0.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.0.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60312",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39267549"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60313",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39267550"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60314",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Router",
                    "text": "39268619"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General).  Supported versions that are affected are 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4625V-9.7.0-9.7.1",
                    "P-4625V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4625V-9.7.0-9.7.1",
                        "P-4625V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4625V-9.7.0-9.7.1",
                        "P-4625V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60315",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39268692"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster and  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60316",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39268863"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: X Plugin)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: X Plugin)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60317",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39270237"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/Net)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60318",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Data Integrator",
                    "text": "39270761"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Data Integrator accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2196V-14.1.2.0.0",
                    "P-2196V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.3,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60319",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Data Integrator",
                    "text": "39270817"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator.  While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2196V-14.1.2.0.0",
                    "P-2196V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60320",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Data Integrator",
                    "text": "39270928"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2196V-14.1.2.0.0",
                    "P-2196V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60321",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Manufacturing",
                    "text": "39393029"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).   The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-321V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-321V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-321V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60322",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Manager",
                    "text": "39271019"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Manager accessible data as well as  unauthorized read access to a subset of Oracle Applications Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-99V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-99V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-99V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60323",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39271534"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60324",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39272322"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60325",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272792"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60326",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272803"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60327",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272822"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60328",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272838"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60329",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39272845"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60330",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39274584"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60331",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39282350"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60332",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39282368"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.0.0-8.0.47",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Group Replication GCS)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60333",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39284180"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60334",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39284235"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60335",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39284253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60336",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Manufacturing",
                    "text": "39393051"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).   The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-321V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-321V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-321V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60337",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Manufacturing",
                    "text": "39393094"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).   The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-321V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-321V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-321V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60338",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Manufacturing",
                    "text": "39393174"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).   The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Project Manufacturing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Manufacturing. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-321V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-321V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.6,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-321V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60339",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Manufacturing",
                    "text": "39393138"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).   The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-321V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-321V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-321V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60340",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Costing",
                    "text": "39391866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Project Costing.  Successful attacks of this vulnerability can result in takeover of Oracle Project Costing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1287V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1287V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1287V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60342",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39284925"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60343",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39284970"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-14.1.1.0.0",
                    "P-5242V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60344",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (France)",
                    "text": "39286371"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle HRMS (France) accessible data as well as  unauthorized read access to a subset of Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-998V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-998V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-998V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60345",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286510"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60346",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
                    "text": "39286573"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability Security).   The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4781V-9.2.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4781V-9.2.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4781V-9.2.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60347",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
                    "text": "39286591"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).   The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4781V-9.2.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4781V-9.2.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.6,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4781V-9.2.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60348",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286633"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60349",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286673"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60350",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286686"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper.  While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60351",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286703"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data as well as  unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60352",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286708"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60353",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286717"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60354",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286736"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60355",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39286789"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60356",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39286791"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60357",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39288404"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-17.0-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60358",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39288884"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60359",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39288916"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60360",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39288920"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60361",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39288936"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60362",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39288943"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60363",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HTTP Server",
                    "text": "39288945"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1042(Oracle HTTP Server_Apache Plugin)V-14.1.2.0.0",
                    "P-1042(Oracle HTTP Server_Apache Plugin)V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1042(Oracle HTTP Server_Apache Plugin)V-14.1.2.0.0",
                        "P-1042(Oracle HTTP Server_Apache Plugin)V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1042(Oracle HTTP Server_Apache Plugin)V-14.1.2.0.0",
                        "P-1042(Oracle HTTP Server_Apache Plugin)V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60364",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HTTP Server",
                    "text": "39288954"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Weblogic Server Proxy Plug-in",
                    "text": "39581636"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1042(Oracle HTTP Server_Core)V-12.2.1.4.0",
                    "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-14.1.2.0.0",
                    "P-1042(Oracle HTTP Server_Core)V-14.1.2.0.0",
                    "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1042(Oracle HTTP Server_Core)V-12.2.1.4.0",
                        "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-14.1.2.0.0",
                        "P-1042(Oracle HTTP Server_Core)V-14.1.2.0.0",
                        "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1042(Oracle HTTP Server_Core)V-12.2.1.4.0",
                        "P-1042(Oracle HTTP Server_Core)V-14.1.2.0.0"
                    ]
                },
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-14.1.2.0.0",
                        "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60365",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Weblogic Server Proxy Plug-in",
                    "text": "39600446"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle HTTP Server",
                    "text": "39288957"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers).   The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in.  While the vulnerability is in Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data as well as  unauthorized access to critical data or complete access to all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1042(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server)V-12.2.1.4.0",
                    "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-15.1.1.0.0",
                    "P-1042(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server)V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1042(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server)V-14.1.2.0.0",
                        "P-1042(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server)V-12.2.1.4.0",
                        "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1042(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server)V-14.1.2.0.0",
                        "P-1042(Oracle HTTP Server_Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server)V-12.2.1.4.0",
                        "P-1042(Oracle Weblogic Server Proxy Plug-in_WebLogic Server Proxy Plug-In for Third-Party Web Servers)V-15.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60366",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289022"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.  While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60367",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289035"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60368",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289068"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60369",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289072"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.  While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60370",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289203"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60371",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java.  While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60372",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289214"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60373",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289242"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60374",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289256"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60375",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289260"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60376",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289265"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60377",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289270"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as  unauthorized access to critical data or complete access to all Service Delivery Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60378",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289283"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60379",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289288"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60380",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289298"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60381",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289316"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60382",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289319"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60383",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289351"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Service Delivery Platform executes to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as  unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60384",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289377"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60385",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289385"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60386",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289389"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60387",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289391"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60388",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289402"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60389",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289407"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60394",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39290051"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable).  Supported versions that are affected are 21.3-21.21 and  23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60395",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39290065"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Admin Server  Executable).  Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and  23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60396",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39290170"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Distribution Server executable).  Supported versions that are affected are 21.3-21.21 and  23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60397",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39290210"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable).  Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and  23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate executes to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60398",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39290233"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices).  Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and  23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60399",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39290248"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Receiver Service Executable).  Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and  23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60400",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39290270"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable).  Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and  23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60401",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290539"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database.  While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60402",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290557"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.  While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60403",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290577"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60404",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290599"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60405",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290617"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database.  While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.8,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60406",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290633"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60407",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290649"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database.  While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60408",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290664"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60409",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290685"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database.  While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of TimesTen In-Memory Database accessible data as well as  unauthorized read access to a subset of TimesTen In-Memory Database accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 5.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60410",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290703"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60411",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of TimesTen In-Memory Database",
                    "text": "39290775"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver).   The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1870V-26.1.1.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1870V-26.1.1.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1870V-26.1.1.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60416",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39291221"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60417",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291248"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60418",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291249"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60419",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291251"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60420",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as  unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60421",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291257"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as  unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60422",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291259"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).   The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as  unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60423",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291270"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60424",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291271"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60425",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291273"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60426",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291283"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as  unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60427",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291284"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as  unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60428",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291286"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as  unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60429",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291287"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60430",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39291288"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60431",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HTTP Server",
                    "text": "39291294"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1042(Oracle HTTP Server_mod_proxy)V-12.2.1.4.0",
                    "P-1042(Oracle HTTP Server_mod_proxy)V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1042(Oracle HTTP Server_mod_proxy)V-12.2.1.4.0",
                        "P-1042(Oracle HTTP Server_mod_proxy)V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1042(Oracle HTTP Server_mod_proxy)V-12.2.1.4.0",
                        "P-1042(Oracle HTTP Server_mod_proxy)V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60433",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Transportation Management",
                    "text": "39291993"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Integration).   The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1991V-6.5.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1991V-6.5.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1991V-6.5.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60434",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Transportation Management",
                    "text": "39292223"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication).   The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1991V-6.5.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1991V-6.5.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1991V-6.5.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60435",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39292570"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60436",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39293342"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60437",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39293343"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 8.7 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60438",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HTTP Server",
                    "text": "39293347"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1042(Oracle HTTP Server_mod_ssl)V-12.2.1.4.0",
                    "P-1042(Oracle HTTP Server_mod_ssl)V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1042(Oracle HTTP Server_mod_ssl)V-14.1.2.0.0",
                        "P-1042(Oracle HTTP Server_mod_ssl)V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1042(Oracle HTTP Server_mod_ssl)V-14.1.2.0.0",
                        "P-1042(Oracle HTTP Server_mod_ssl)V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60439",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39293354"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60440",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39293365"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60441",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39293366"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60442",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39293367"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60443",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39293369"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60444",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39293372"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60445",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293383"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60446",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293391"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60447",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293400"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60448",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39293406"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60449",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39293410"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content.  While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60450",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39293411"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60451",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293414"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data as well as  unauthorized update, insert or delete access to some of WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60452",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293415"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data as well as  unauthorized update, insert or delete access to some of WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60454",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HTTP Server",
                    "text": "39293840"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1042(Oracle HTTP Server_Core)V-12.2.1.4.0",
                    "P-1042(Oracle HTTP Server_Core)V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1042(Oracle HTTP Server_Core)V-12.2.1.4.0",
                        "P-1042(Oracle HTTP Server_Core)V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1042(Oracle HTTP Server_Core)V-12.2.1.4.0",
                        "P-1042(Oracle HTTP Server_Core)V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60455",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39293841"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60456",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293856"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60457",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293860"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60458",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293861"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60459",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293862"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60460",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293864"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60461",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60462",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39293875"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60463",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293880"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60464",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293881"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60465",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293883"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60466",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293886"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60467",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293891"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60468",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293893"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data as well as  unauthorized update, insert or delete access to some of WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60469",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293894"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as  unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60470",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293896"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as  unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60471",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293899"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the WebCenter Content: Imaging executes to compromise WebCenter Content: Imaging.  While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60472",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39293901"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60489",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne CRM Foundation",
                    "text": "39294607"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne CRM Foundation.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne CRM Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4717V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4717V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4717V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60490",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne CRM Foundation",
                    "text": "39294610"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne CRM Foundation.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne CRM Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4717V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4717V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4717V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60491",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Inbound Telephony",
                    "text": "39112442"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data as well as  unauthorized read access to a subset of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-265V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-265V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-265V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60492",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne HCM Foundation",
                    "text": "39294629"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundation).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne HCM Foundation.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne HCM Foundation and  unauthorized read access to a subset of JD Edwards EnterpriseOne HCM Foundation accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4740V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4740V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4740V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60493",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Human Resources Management",
                    "text": "39294653"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4742V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4742V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4742V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60494",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne General Ledger",
                    "text": "39294657"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne General Ledger as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne General Ledger accessible data and  unauthorized read access to a subset of JD Edwards EnterpriseOne General Ledger accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4737V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4737V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4737V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60495",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Requirements Planning",
                    "text": "39294664"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product of Oracle JD Edwards (component: Requirements Planning).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Requirements Planning.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Requirements Planning. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4763V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4763V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4763V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60496",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Advanced Pricing - Procurement",
                    "text": "39294666"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Advanced Pricing - Procurement product of Oracle JD Edwards (component: Advanced Pricing).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Advanced Pricing - Procurement.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Advanced Pricing - Procurement. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4694V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4694V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4694V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60497",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne CRM Foundation",
                    "text": "39294670"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne CRM Foundation.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne CRM Foundation. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4717V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4717V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4717V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60498",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Human Resources Management",
                    "text": "39294673"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Human Resources Management.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4742V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4742V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4742V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60499",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Solution Advisor",
                    "text": "39294809"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Oracle JD Edwards (component: Solution Advisor).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Solution Advisor.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Solution Advisor. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4775V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4775V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4775V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60501",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39295134"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Service Delivery Platform executes to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Service Delivery Platform accessible data as well as  unauthorized read access to a subset of Service Delivery Platform accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60502",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39295164"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60503",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of WebCenter Content: Imaging",
                    "text": "39295174"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging.  Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4576V-12.2.1.4.0",
                    "P-4576V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4576V-12.2.1.4.0",
                        "P-4576V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60519",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39296986"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60520",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Unified Directory",
                    "text": "39296987"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as  unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9118V-12.2.1.4.0",
                    "P-9118V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9118V-12.2.1.4.0",
                        "P-9118V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60521",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Pricing",
                    "text": "39297005"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Pricing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data as well as  unauthorized read access to a subset of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-495V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-495V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-495V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60522",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39297056"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60523",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39297057"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60524",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39297068"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60525",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39297070"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60526",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Java SE",
                    "text": "39298386"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Java SE (component: Installation).  Supported versions that are affected are Oracle Java SE: 8u491 and  8u491-perf. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-856V-8u491-perf",
                    "P-856V-8u491"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-856V-8u491-perf",
                        "P-856V-8u491"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU270"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-856V-8u491-perf",
                        "P-856V-8u491"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60527",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39298406"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).  Supported versions that are affected are 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60528",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39298410"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).  Supported versions that are affected are 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60529",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39298415"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).  Supported versions that are affected are 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60530",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HTTP Server",
                    "text": "39298431"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1042(Oracle HTTP Server_mod_http2.so)V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1042(Oracle HTTP Server_mod_http2.so)V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1042(Oracle HTTP Server_mod_http2.so)V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60531",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299882"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60532",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299898"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60533",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299904"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.0 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60534",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299905"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as  unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60535",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299920"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60536",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299923"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60537",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39300003"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer.  While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10198V-14.1.2.0.0",
                    "P-10198V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60538",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SOA Suite",
                    "text": "39300005"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1162V-14.1.2.0.0",
                    "P-1162V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60539",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SOA Suite",
                    "text": "39300024"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1162V-14.1.2.0.0",
                    "P-1162V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60540",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SOA Suite",
                    "text": "39300026"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite.  While the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data as well as  unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1162V-14.1.2.0.0",
                    "P-1162V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60541",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SOA Suite",
                    "text": "39300027"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1162V-14.1.2.0.0",
                    "P-1162V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60542",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
                    "text": "39300029"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Business Process Management Suite.  While the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5325V-12.2.1.4.0",
                    "P-5325V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5325V-14.1.2.0.0",
                        "P-5325V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5325V-14.1.2.0.0",
                        "P-5325V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60543",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SOA Suite",
                    "text": "39300038"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1162V-14.1.2.0.0",
                    "P-1162V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60544",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SOA Suite",
                    "text": "39300041"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SOA Suite. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1162V-14.1.2.0.0",
                    "P-1162V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60545",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39300044"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10198V-14.1.2.0.0",
                    "P-10198V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60546",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SOA Suite",
                    "text": "39300053"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1162V-14.1.2.0.0",
                    "P-1162V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60547",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39300064"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer.  While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10198V-14.1.2.0.0",
                    "P-10198V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60548",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SOA Suite",
                    "text": "39300066"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite.  While the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1162V-14.1.2.0.0",
                    "P-1162V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1162V-14.1.2.0.0",
                        "P-1162V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60549",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39300074"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10198V-14.1.2.0.0",
                    "P-10198V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60550",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300080"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60551",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300083"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60552",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300088"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60553",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300089"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60554",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300090"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60555",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300091"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60556",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300104"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60557",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300114"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60558",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300115"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60559",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39300373"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60560",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39301046"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60561",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301078"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60562",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301101"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60563",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301169"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60564",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301173"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60565",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301300"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60566",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301302"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60567",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39301367"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60568",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301369"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60569",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Cluster",
                    "text": "39311028"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator).  Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Cluster accessible data. CVSS 3.1 Base Score 5.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8479V-8.4.0-8.4.10",
                    "P-8479V-8.0.0-8.0.47",
                    "P-8479V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8479V-8.4.0-8.4.10",
                        "P-8479V-8.0.0-8.0.47",
                        "P-8479V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8479V-8.4.0-8.4.10",
                        "P-8479V-8.0.0-8.0.47",
                        "P-8479V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60570",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39311207"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Libraries).  Supported versions that are affected are 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60571",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SDP Number Portability",
                    "text": "39313209"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Installation).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-217V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-217V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-217V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60572",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Suite Integrated SOA Gateway",
                    "text": "39314615"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as  unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4569V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4569V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4569V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60573",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Partner Management",
                    "text": "39314829"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Partner Dashboard).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Partner Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Partner Management accessible data as well as  unauthorized read access to a subset of Oracle Partner Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Partner Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1065V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1065V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1065V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60574",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Content Manager",
                    "text": "39314876"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Content Manager accessible data as well as  unauthorized read access to a subset of Oracle Content Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Content Manager. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1145V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1145V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1145V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60575",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Workflow",
                    "text": "39315172"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as  unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-174V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-174V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-174V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60576",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Command Center Framework",
                    "text": "39315596"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).   The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13788V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13788V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13788V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60577",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Command Center Framework",
                    "text": "39315608"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).   The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data as well as  unauthorized update, insert or delete access to some of Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13788V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13788V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13788V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60578",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Command Center Framework",
                    "text": "39315632"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).   The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.  While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data as well as  unauthorized update, insert or delete access to some of Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13788V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13788V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13788V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60579",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Command Center Framework",
                    "text": "39315744"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).   The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework.  While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as  unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13788V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13788V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13788V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60580",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Command Center Framework",
                    "text": "39315985"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).   The supported version that is affected is V16. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13788V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13788V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13788V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60581",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Command Center Framework",
                    "text": "39315992"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).   The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13788V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13788V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13788V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60582",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Command Center Framework",
                    "text": "39316015"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).   The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13788V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13788V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13788V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60583",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Transportation Management",
                    "text": "39316629"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install).   The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in takeover of Oracle Transportation Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1991V-6.5.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1991V-6.5.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1991V-6.5.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60584",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Transportation Management",
                    "text": "39316675"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management).   The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1991V-6.5.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1991V-6.5.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1991V-6.5.3"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Dennis Tighe"
                    ]
                },
                {
                    "names": [
                        "Pucagit"
                    ],
                    "organization": "CyStack"
                }
            ],
            "cve": "CVE-2026-60585",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39319907"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60586",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39320456"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60587",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Foundation",
                    "text": "39321950"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Project Definition).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Foundation.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Project Foundation accessible data as well as  unauthorized read access to a subset of Oracle Project Foundation accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Foundation. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1293V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1293V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1293V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60588",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Asset Management",
                    "text": "39321977"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Asset Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1142V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1142V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1142V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60593",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Staffing Front Office",
                    "text": "39323532"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office product of Oracle PeopleSoft (component: Staffing Front Office).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Staffing Front Office accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5026V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5026V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5026V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60594",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39323542"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60595",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Pay/Bill Management",
                    "text": "39323589"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Pay/Bill Management executes to compromise PeopleSoft Enterprise FIN Pay/Bill Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Pay/Bill Management accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5007V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5007V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5007V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60596",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN eSettlements",
                    "text": "39323655"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN eSettlements executes to compromise PeopleSoft Enterprise FIN eSettlements.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 2.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4987V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4987V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.3,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4987V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60597",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Cash Management",
                    "text": "39324095"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Cash Management.  While the vulnerability is in PeopleSoft Enterprise FIN Cash Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Cash Management accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Cash Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4979V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4979V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4979V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60598",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Student Records",
                    "text": "39324699"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Records. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5182V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5182V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5182V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60599",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Student Records",
                    "text": "39324754"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Student Records.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Student Records accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5182V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5182V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5182V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60600",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Project Costing",
                    "text": "39324878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Project Costing executes to compromise PeopleSoft Enterprise FIN Project Costing.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Project Costing. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5013V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5013V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5013V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60601",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Common Objects",
                    "text": "39324921"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Common Objects executes to compromise PeopleSoft Enterprise FIN Common Objects.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects accessible data. CVSS 3.1 Base Score 4.4 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8923V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8923V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8923V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60602",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Student Financials",
                    "text": "39324936"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Billing).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Financials.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5180V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5180V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5180V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60603",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Student Records",
                    "text": "39324950"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Records. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5182V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5182V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5182V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60604",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39325116"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60605",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Student Records",
                    "text": "39325132"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5182V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5182V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5182V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60606",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CC Common Application Objects",
                    "text": "39325134"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CC Common Application Objects accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8911V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8911V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8911V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60607",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Financial Aid",
                    "text": "39325166"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5178V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5178V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5178V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60608",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Financial Aid",
                    "text": "39325203"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need Analysis).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial Aid.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5178V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5178V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5178V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60609",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39325210"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60610",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39325250"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60611",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39325258"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60612",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Financial Aid",
                    "text": "39325281"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5178V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5178V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5178V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60613",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Student Records",
                    "text": "39325354"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Records. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5182V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5182V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5182V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60614",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39325361"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60615",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39325436"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60616",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39325455"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60617",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39325466"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60618",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Procurement and Subcontract Management",
                    "text": "39325870"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Procurement and Subcontract Management.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Procurement and Subcontract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4753V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4753V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4753V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60619",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne HCM Foundation",
                    "text": "39325874"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne HCM Foundation.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne HCM Foundation. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4740V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4740V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4740V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60620",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Configurator",
                    "text": "39325878"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Configurator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Configurator as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Configurator accessible data and  unauthorized read access to a subset of JD Edwards EnterpriseOne Configurator accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4710V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4710V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4710V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60621",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
                    "text": "39325925"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security).   The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4781V-9.2.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4781V-9.2.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4781V-9.2.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60622",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39326396"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60623",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39327277"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60624",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39328305"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60625",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Data Integrator",
                    "text": "39328436"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2196V-14.1.2.0.0",
                    "P-2196V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60626",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
                    "text": "39328712"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).   The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.0 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4781V-9.2.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4781V-9.2.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.0,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4781V-9.2.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60627",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
                    "text": "39328714"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).   The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4781V-9.2.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4781V-9.2.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4781V-9.2.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60628",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
                    "text": "39328771"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).   The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4781V-9.2.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4781V-9.2.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU275"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4781V-9.2.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60629",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39328801"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data as well as  unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60630",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle APEX",
                    "text": "39329404"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle APEX (component: Installation).  Supported versions that are affected are 24.1, 24.2 and  26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle APEX executes to compromise Oracle APEX.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle APEX accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1348V-24.1",
                    "P-1348V-24.2",
                    "P-1348V-26.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1348V-24.2",
                        "P-1348V-26.1",
                        "P-1348V-24.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1348V-24.2",
                        "P-1348V-26.1",
                        "P-1348V-24.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60631",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39336416"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60632",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39336418"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60633",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39336420"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60634",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39336421"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60635",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39337856"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60636",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39337859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60637",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39337865"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60638",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39337866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60639",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340113"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60640",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340115"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60641",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340118"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60642",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340121"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60643",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340124"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60644",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340129"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60645",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340132"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60646",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340135"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60647",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340137"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60648",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340144"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60649",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340145"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60650",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340147"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60651",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340148"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60652",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340150"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60653",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340153"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60654",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340155"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60655",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340157"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60656",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340159"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60657",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340378"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60658",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39340380"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60659",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Solaris",
                    "text": "39340657"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems).   The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10006V-11.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10006V-11.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU273"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10006V-11.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60661",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Solaris",
                    "text": "39340673"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems).   The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10006V-11.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10006V-11.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU273"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10006V-11.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60663",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39341103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.  While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60664",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39342202"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60665",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Global Payroll Switzerland",
                    "text": "39349053"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Switzerland.  While the vulnerability is in PeopleSoft Enterprise HCM Global Payroll Switzerland, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5068V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5068V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5068V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60666",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Human Resources",
                    "text": "39349663"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via Oracle Net to compromise PeopleSoft Enterprise HCM Human Resources.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Human Resources accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5071V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5071V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5071V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60667",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Human Resources",
                    "text": "39349689"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise PeopleSoft Enterprise HCM Human Resources.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Human Resources accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise HCM Human Resources. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5071V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5071V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5071V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60668",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Human Resources",
                    "text": "39349695"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: French Public Sector Specific).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Human Resources accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5071V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5071V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5071V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60669",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Global Payroll Mexico",
                    "text": "39349715"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Mexico.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Mexico accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise HCM Global Payroll Mexico. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5063V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5063V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5063V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60670",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Technology Stack",
                    "text": "39351079"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology Stack.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Technology Stack. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1745V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1745V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1745V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60671",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39351180"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition as well as  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data and  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU217"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60673",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39351377"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU217"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60674",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39351443"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU217"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60675",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39351706"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60676",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39351738"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60677",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Common Application Components",
                    "text": "39351755"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Common Application Components product of Oracle E-Business Suite (component: Oracle Common Modules).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Application Components.  While the vulnerability is in Oracle Common Application Components, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Common Application Components accessible data as well as  unauthorized access to critical data or complete access to all Oracle Common Application Components accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Application Components. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-83V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-83V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-83V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60678",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle General Ledger",
                    "text": "39353691"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle General Ledger.  Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-500V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-500V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-500V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60681",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Regulatory Management",
                    "text": "39354164"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Regulatory Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-280V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-280V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-280V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60683",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Regulatory Management",
                    "text": "39354272"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management.  While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-280V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-280V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-280V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60684",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39137177"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).  Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as  unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.8-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.8-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.8-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60685",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSupport",
                    "text": "39354555"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle iSupport accessible data as well as  unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-381V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-381V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-381V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60686",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle U.S. Federal Financials",
                    "text": "39354581"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle U.S. Federal Financials accessible data as well as  unauthorized access to critical data or complete access to all Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-935V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-935V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-935V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60687",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle U.S. Federal Financials",
                    "text": "39354586"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle U.S. Federal Financials.  While the vulnerability is in Oracle U.S. Federal Financials, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-935V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-935V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-935V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60688",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Scheduler",
                    "text": "39354866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scheduler.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Scheduler accessible data as well as  unauthorized read access to a subset of Oracle Scheduler accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scheduler. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-756V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-756V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-756V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60689",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39354994"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60690",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39355025"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60691",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Content Manager",
                    "text": "39355033"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Content Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Content Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1145V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1145V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1145V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60692",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Asset Management",
                    "text": "39355216"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Asset Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1142V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1142V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1142V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60694",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Asset Management",
                    "text": "39355363"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Asset Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1142V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1142V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1142V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60695",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Asset Management",
                    "text": "39355386"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Asset Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1142V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1142V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1142V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60697",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Site Hub",
                    "text": "39355473"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Site Hub accessible data as well as  unauthorized read access to a subset of Oracle Site Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Site Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1676V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1676V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1676V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60700",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Universal Work Queue",
                    "text": "39355575"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: UWQ Server Issues).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as  unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-778V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-778V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-778V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60701",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Universal Work Queue",
                    "text": "39355599"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue.  Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-778V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-778V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-778V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60703",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Interaction Blending",
                    "text": "39355651"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Interaction Blending executes to compromise Oracle Interaction Blending.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Interaction Blending accessible data as well as  unauthorized access to critical data or complete access to all Oracle Interaction Blending accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-182V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-182V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-182V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60704",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39355944"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60705",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39356046"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60706",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Inventory",
                    "text": "39356078"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Inventory product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Inventory.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Inventory accessible data as well as  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Inventory accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-733V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-733V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-733V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60708",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Financials",
                    "text": "39356191"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-736V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-736V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-736V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60709",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39356337"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as  unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60710",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle EDI Gateway",
                    "text": "39356820"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle EDI Gateway accessible data as well as  unauthorized access to critical data or complete access to all Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-509V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-509V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-509V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60711",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39357116"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60712",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39357178"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60713",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39357648"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as  unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU276"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60714",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Price Protection",
                    "text": "39357792"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as  unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4347V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4347V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4347V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60717",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Complex Maintenance, Repair and Overhaul",
                    "text": "39360909"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair and Overhaul accessible data as well as  unauthorized read access to a subset of Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1184V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1184V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1184V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Weiheng Qiu"
                    ],
                    "organization": "Vanderbilt University"
                }
            ],
            "cve": "CVE-2026-60718",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39361343"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60719",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39361408"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU217"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60723",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Data Integrator",
                    "text": "39364139"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator.  While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Data Integrator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2196V-14.1.2.0.0",
                    "P-2196V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60724",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Customer Interaction History",
                    "text": "39364273"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data as well as  unauthorized read access to a subset of Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1374V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1374V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1374V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60725",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Router",
                    "text": "39365725"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General).  Supported versions that are affected are 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Router accessible data as well as  unauthorized access to critical data or complete access to all MySQL Router accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4625V-9.7.0-9.7.1",
                    "P-4625V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4625V-9.7.0-9.7.1",
                        "P-4625V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4625V-9.7.0-9.7.1",
                        "P-4625V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60732",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iReceivables",
                    "text": "39366712"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iReceivables accessible data as well as  unauthorized access to critical data or complete access to all Oracle iReceivables accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1106V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1106V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1106V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60734",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Trading Community",
                    "text": "39366729"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Trading Community.  Successful attacks of this vulnerability can result in takeover of Oracle Trading Community. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1137V-12.2.3-12.2.12"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1137V-12.2.3-12.2.12"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1137V-12.2.3-12.2.12"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60735",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Offline",
                    "text": "39366807"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Sales Offline accessible data as well as  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1009V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1009V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1009V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60736",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Intelligence",
                    "text": "39367617"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as  unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-163V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-163V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-163V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60738",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Installed Base",
                    "text": "39367903"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base.  Successful attacks of this vulnerability can result in takeover of Oracle Installed Base. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1118V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1118V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1118V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60739",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Field Service",
                    "text": "39368102"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as  unauthorized update, insert or delete access to some of Oracle Field Service accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-747V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-747V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-747V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60740",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cash Management",
                    "text": "39368887"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cash Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Cash Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Cash Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-968V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-968V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-968V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60741",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cost Management",
                    "text": "39368890"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-569V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-569V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-569V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60744",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cost Management",
                    "text": "39368972"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-569V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-569V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-569V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Pucagit"
                    ],
                    "organization": "CyStack"
                }
            ],
            "cve": "CVE-2026-60747",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39377010"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60749",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Assets",
                    "text": "39382358"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Assets accessible data as well as  unauthorized access to critical data or complete access to all Oracle Assets accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-503V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-503V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-503V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60750",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payroll",
                    "text": "39382388"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll.  While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-506V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-506V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-506V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60755",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Assets",
                    "text": "39382716"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Assets.  Successful attacks of this vulnerability can result in takeover of Oracle Assets. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-503V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-503V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-503V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60756",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle EDI Gateway",
                    "text": "39382767"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle EDI Gateway.  Successful attacks of this vulnerability can result in takeover of Oracle EDI Gateway. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-509V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-509V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-509V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60760",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Asset Management",
                    "text": "39383123"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1142V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1142V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1142V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60761",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications DBA",
                    "text": "39383290"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Applications DBA executes to compromise Oracle Applications DBA.  While the vulnerability is in Oracle Applications DBA, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-166V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-166V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-166V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60762",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Technology Stack",
                    "text": "39383391"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Applications Technology Stack executes to compromise Oracle Applications Technology Stack.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Applications Technology Stack accessible data as well as  unauthorized access to critical data or complete access to all Oracle Applications Technology Stack accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1745V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1745V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1745V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60763",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Manager",
                    "text": "39383431"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Manager executes to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-99V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-99V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-99V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60764",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financials Common Modules",
                    "text": "39383482"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1320V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1320V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1320V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60768",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39383544"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Graph / Charting).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as  unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60770",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39383566"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60771",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Complex Maintenance, Repair and Overhaul",
                    "text": "39383608"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Complex Maintenance, Repair and Overhaul accessible data as well as  unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1184V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1184V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1184V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60772",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financials Common Modules",
                    "text": "39383617"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as  unauthorized read access to a subset of Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1320V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1320V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1320V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60773",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39383633"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Application Object Library.  While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60774",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39383652"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl.  Advanced]).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60775",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Pasta",
                    "text": "39383669"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Pasta executes to compromise Pasta.  Successful attacks of this vulnerability can result in takeover of Pasta. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1195V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1195V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1195V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60776",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39383691"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60777",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39383806"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as  unauthorized read access to a subset of Oracle Application Object Library accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Object Library. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60778",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payments",
                    "text": "39383820"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as  unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-378V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-378V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-378V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60780",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Workflow",
                    "text": "39383887"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-174V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-174V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-174V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60783",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iReceivables",
                    "text": "39383985"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables.  Successful attacks of this vulnerability can result in takeover of Oracle iReceivables. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1106V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1106V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1106V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60784",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Trading Community",
                    "text": "39383988"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Trading Community accessible data as well as  unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1137V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1137V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1137V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60785",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iReceivables",
                    "text": "39383993"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iReceivables.  Successful attacks of this vulnerability can result in takeover of Oracle iReceivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1106V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1106V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1106V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60786",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Receivables",
                    "text": "39384005"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Receivables.  Successful attacks of this vulnerability can result in takeover of Oracle Receivables. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-505V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-505V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-505V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60787",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Receivables",
                    "text": "39384006"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Receivables.  Successful attacks of this vulnerability can result in takeover of Oracle Receivables. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-505V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-505V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-505V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60788",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Offline",
                    "text": "39384230"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Sales Offline accessible data as well as  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Sales Offline. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1009V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1009V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1009V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60789",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Offline",
                    "text": "39384242"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in takeover of Oracle Sales Offline. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1009V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1009V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1009V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60790",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Offline",
                    "text": "39384250"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Sales Offline.  While the vulnerability is in Oracle Sales Offline, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Sales Offline. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1009V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1009V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1009V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60793",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle TeleSales",
                    "text": "39384383"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle TeleSales.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle TeleSales accessible data as well as  unauthorized access to critical data or complete access to all Oracle TeleSales accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-296V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-296V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-296V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60794",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle TeleSales",
                    "text": "39384389"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle TeleSales.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle TeleSales accessible data as well as  unauthorized read access to a subset of Oracle TeleSales accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-296V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-296V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-296V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60795",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSetup",
                    "text": "39384481"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iSetup accessible data as well as  unauthorized access to critical data or complete access to all Oracle iSetup accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-841V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-841V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-841V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60799",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Compensation Workbench",
                    "text": "39384525"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as  unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4427V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4427V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4427V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60800",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Compensation Workbench",
                    "text": "39384541"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as  unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4427V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4427V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4427V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60801",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Intelligence",
                    "text": "39384605"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as  unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-163V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-163V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-163V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60802",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Intelligence",
                    "text": "39384607"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Intelligence.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle E-Business Intelligence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data as well as  unauthorized read access to a subset of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-163V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-163V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-163V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60804",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Intelligence",
                    "text": "39384614"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 2.0 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-163V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-163V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.0,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-163V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60805",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cost Management",
                    "text": "39384681"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Cost Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cost Management. CVSS 3.1 Base Score 6.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-569V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-569V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-569V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60806",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cost Management",
                    "text": "39384720"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Costing Transaction Errors).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management.  Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-569V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-569V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-569V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60807",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39384765"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60810",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Supply Chain Trading Connector",
                    "text": "39384851"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data as well as  unauthorized update, insert or delete access to some of Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1311V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1311V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1311V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60811",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Supply Chain Trading Connector",
                    "text": "39384856"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Supply Chain Trading Connector accessible data as well as  unauthorized read access to a subset of Oracle Supply Chain Trading Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Supply Chain Trading Connector. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1311V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1311V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1311V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60812",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Supply Chain Trading Connector",
                    "text": "39384859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1311V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1311V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1311V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60813",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iStore",
                    "text": "39384959"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks of this vulnerability can result in takeover of Oracle iStore. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-384V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-384V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-384V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60815",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iStore",
                    "text": "39385005"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle iStore accessible data as well as  unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-384V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-384V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-384V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60816",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iStore",
                    "text": "39385008"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-384V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-384V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-384V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60817",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iStore",
                    "text": "39385010"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as  unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-384V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-384V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-384V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60823",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSupport",
                    "text": "39385400"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iSupport accessible data as well as  unauthorized access to critical data or complete access to all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-381V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-381V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-381V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60824",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSupport",
                    "text": "39385416"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport.  While the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-381V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-381V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-381V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60825",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSupport",
                    "text": "39385437"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport.  Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-381V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-381V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-381V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60826",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSupport",
                    "text": "39385441"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport.  Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-381V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-381V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-381V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60827",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSupport",
                    "text": "39385446"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.4 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-381V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-381V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-381V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60828",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Interaction Blending",
                    "text": "39385484"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Interaction Blending.  Successful attacks of this vulnerability can result in takeover of Oracle Interaction Blending. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-182V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-182V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-182V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60829",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Outbound Telephony",
                    "text": "39385486"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony.  Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-785V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-785V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-785V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60832",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Interaction Blending",
                    "text": "39385573"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via RMI to compromise Oracle Interaction Blending.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Interaction Blending accessible data as well as  unauthorized read access to a subset of Oracle Interaction Blending accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Interaction Blending. CVSS 3.1 Base Score 4.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-182V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-182V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-182V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60833",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Solaris",
                    "text": "39387104"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).   The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10006V-11.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10006V-11.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU273"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10006V-11.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60834",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Solaris",
                    "text": "39387105"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).   The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access via RAD to compromise Oracle Solaris.  While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Solaris accessible data as well as  unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10006V-11.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10006V-11.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU273"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10006V-11.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60835",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Price Protection",
                    "text": "39388985"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4347V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4347V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4347V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60836",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HCM Common Architecture",
                    "text": "39388993"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Common Architecture.  Successful attacks of this vulnerability can result in takeover of Oracle HCM Common Architecture. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2021V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2021V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2021V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60837",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Price Protection",
                    "text": "39389010"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Price Protection executes to compromise Oracle Price Protection.  While the vulnerability is in Oracle Price Protection, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as  unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4347V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4347V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4347V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60838",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Price Protection",
                    "text": "39389149"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as  unauthorized read access to a subset of Oracle Price Protection accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4347V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4347V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4347V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60840",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Demand Signal Repository",
                    "text": "39389742"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Demand Signal Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4546V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4546V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4546V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60842",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Knowledge Management",
                    "text": "39389795"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search).  Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data as well as  unauthorized read access to a subset of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1351V-12.2.5-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1351V-12.2.5-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1351V-12.2.5-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60843",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Citizen Interaction Center",
                    "text": "39389834"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Citizen Interaction Center product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Citizen Interaction Center.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Citizen Interaction Center accessible data as well as  unauthorized access to critical data or complete access to all Oracle Citizen Interaction Center accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1185V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1185V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1185V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60844",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Customer Support",
                    "text": "39389864"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Support.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Customer Support accessible data as well as  unauthorized access to critical data or complete access to all Oracle Customer Support accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1779V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1779V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1779V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60845",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Mobile Application Server",
                    "text": "39390222"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA General Bugs).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server.  Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-995V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-995V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-995V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60846",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Mobile Application Server",
                    "text": "39390258"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Mobile Application Server accessible data as well as  unauthorized update, insert or delete access to some of Oracle Mobile Application Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Mobile Application Server. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-995V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-995V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-995V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60847",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Entry",
                    "text": "39390351"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Entry product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Entry executes to compromise Oracle Order Entry.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Order Entry accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Order Entry. CVSS 3.1 Base Score 3.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-513V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-513V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.4,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-513V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60848",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Contracts",
                    "text": "39390369"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Contracts accessible data as well as  unauthorized access to critical data or complete access to all Oracle Project Contracts accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-799V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-799V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-799V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60852",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Lease and Finance Management",
                    "text": "39390449"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Lease and Finance Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Lease and Finance Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1056V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1056V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1056V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60854",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Quality",
                    "text": "39390608"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Quality.  While the vulnerability is in Oracle Quality, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Quality accessible data as well as  unauthorized update, insert or delete access to some of Oracle Quality accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Quality. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-214V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-214V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-214V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60855",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Quality",
                    "text": "39390673"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality.  Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-214V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-214V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-214V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60857",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contracts Integration",
                    "text": "39390709"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data as well as  unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-499V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-499V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-499V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60859",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Quoting",
                    "text": "39390800"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quoting.  Successful attacks of this vulnerability can result in takeover of Oracle Quoting. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1296V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1296V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1296V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60862",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Management",
                    "text": "39391097"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management.  While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-497V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-497V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-497V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60863",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Pricing",
                    "text": "39391101"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing.  Successful attacks of this vulnerability can result in takeover of Oracle Advanced Pricing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-495V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-495V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-495V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60864",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Management",
                    "text": "39391113"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management.  While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Order Management accessible data as well as  unauthorized read access to a subset of Oracle Order Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-497V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-497V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-497V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60867",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Pricing",
                    "text": "39391168"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Pricing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-495V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-495V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-495V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60868",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Pricing",
                    "text": "39391178"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation).  Supported versions that are affected are 12.2.14-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing.  While the vulnerability is in Oracle Advanced Pricing, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-495V-12.2.14-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-495V-12.2.14-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-495V-12.2.14-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60870",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Pricing",
                    "text": "39391194"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-495V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-495V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-495V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60871",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Risk Management",
                    "text": "39391281"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Risk Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Risk Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Risk Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1172V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1172V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1172V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60872",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Management",
                    "text": "39391331"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management.  Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-497V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-497V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-497V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60875",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Trade Management",
                    "text": "39391499"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-765V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-765V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-765V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60877",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Trade Management",
                    "text": "39391560"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-765V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-765V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-765V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60880",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Work in Process",
                    "text": "39392003"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process.  Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-572V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-572V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-572V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60886",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Work in Process",
                    "text": "39392088"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Work in Process accessible data as well as  unauthorized update, insert or delete access to some of Oracle Work in Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-572V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-572V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-572V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60888",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Work in Process",
                    "text": "39392164"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-572V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-572V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-572V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60890",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payroll",
                    "text": "39392184"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll.  Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-506V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-506V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-506V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60891",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Work in Process",
                    "text": "39392191"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-572V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-572V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 1.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-572V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60892",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (Norway)",
                    "text": "39392241"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll).  Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway).  Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Norway). CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1645V-12.2.8-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1645V-12.2.8-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1645V-12.2.8-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60893",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payroll",
                    "text": "39392260"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll.  While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-506V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-506V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-506V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60894",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payroll",
                    "text": "39392282"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll.  Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-506V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-506V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-506V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60896",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Work in Process",
                    "text": "39392303"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Work in Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Work in Process. CVSS 3.1 Base Score 3.6 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-572V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-572V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.6,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-572V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60897",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payroll",
                    "text": "39392447"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll.  Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-506V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-506V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-506V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60898",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Warehouse Management",
                    "text": "39392450"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management.  Successful attacks of this vulnerability can result in takeover of Oracle Warehouse Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-385V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-385V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-385V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60899",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HCM Configuration Workbench",
                    "text": "39392610"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HCM Configuration Workbench accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2011V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2011V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2011V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60900",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HCM Configuration Workbench",
                    "text": "39392783"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench.  Successful attacks of this vulnerability can result in takeover of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2011V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2011V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2011V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60901",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Intelligence",
                    "text": "39392808"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.  Successful attacks of this vulnerability can result in takeover of Oracle Project Intelligence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1292V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1292V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1292V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60904",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Installed Base",
                    "text": "39392956"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as  unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1118V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1118V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1118V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60907",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Installed Base",
                    "text": "39393219"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).  Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as  unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1118V-12.2.4-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1118V-12.2.4-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.0,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1118V-12.2.4-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60908",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Installed Base",
                    "text": "39393303"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Installed Base accessible data as well as  unauthorized update, insert or delete access to some of Oracle Installed Base accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1118V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1118V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1118V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60910",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Property Manager",
                    "text": "39393373"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Property Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-44V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-44V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-44V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60911",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Property Manager",
                    "text": "39393398"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Property Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Property Manager accessible data as well as  unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-44V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-44V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-44V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60912",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Property Manager",
                    "text": "39393412"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Property Manager accessible data as well as  unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-44V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-44V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-44V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60913",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Property Manager",
                    "text": "39393422"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Property Manager executes to compromise Oracle Property Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-44V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-44V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 1.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-44V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60917",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Inventory Management",
                    "text": "39393487"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-508V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-508V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-508V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60918",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Shipping Execution",
                    "text": "39393694"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Shipping Execution.  Successful attacks of this vulnerability can result in takeover of Oracle Shipping Execution. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-996V-12.2.12-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-996V-12.2.12-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-996V-12.2.12-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60919",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSupplier Portal",
                    "text": "39393799"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-208V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-208V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-208V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60920",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Customer Care",
                    "text": "39393882"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Care.  Successful attacks of this vulnerability can result in takeover of Oracle Customer Care. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-105V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-105V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-105V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60922",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iSupplier Portal",
                    "text": "39393936"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-208V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-208V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-208V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60923",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Capacity",
                    "text": "39393942"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Capacity product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Capacity.  While the vulnerability is in Oracle Capacity, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Capacity accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-533V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-533V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-533V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60924",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Payroll",
                    "text": "39393961"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll.  Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-196V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-196V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-196V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60925",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Payroll",
                    "text": "39394036"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll.  Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-196V-12.2.4-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-196V-12.2.4-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-196V-12.2.4-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60926",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Payroll",
                    "text": "39394062"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll.  Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-196V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-196V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-196V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60927",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Financials",
                    "text": "39394231"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials.  Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-485V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-485V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-485V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60929",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Financials",
                    "text": "39394273"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-485V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-485V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-485V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60930",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Financials",
                    "text": "39394281"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-485V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-485V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-485V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60931",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Financials",
                    "text": "39394286"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials.  Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-485V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-485V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-485V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60932",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Labor Distribution",
                    "text": "39394303"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution.  Successful attacks of this vulnerability can result in takeover of Oracle Labor Distribution. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-326V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-326V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-326V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60936",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Labor Distribution",
                    "text": "39394373"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Labor Distribution. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-326V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-326V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-326V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60937",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Labor Distribution",
                    "text": "39394375"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-326V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-326V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-326V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60938",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Labor Distribution",
                    "text": "39394378"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Labor Distribution executes to compromise Oracle Labor Distribution.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 4.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-326V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-326V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-326V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60939",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Contracts",
                    "text": "39394534"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Project Contracts accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-799V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-799V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-799V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60940",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Service Contracts",
                    "text": "39394556"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Contracts.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Service Contracts accessible data as well as  unauthorized access to critical data or complete access to all Oracle Service Contracts accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-432V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-432V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-432V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60941",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Service Fulfillment Manager",
                    "text": "39394658"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager.  While the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-129V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-129V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-129V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60942",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Service Fulfillment Manager",
                    "text": "39394667"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-129V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-129V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-129V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60943",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Service Fulfillment Manager",
                    "text": "39394695"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Service Fulfillment Manager. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-129V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-129V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-129V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60945",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Learning Management",
                    "text": "39394723"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Learning Management accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-937V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-937V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-937V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60948",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Learning Management",
                    "text": "39394740"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Learning Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-937V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-937V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-937V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60950",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (Ireland)",
                    "text": "39394888"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Ireland).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle HRMS (Ireland) accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1166V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1166V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1166V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60951",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Time and Labor",
                    "text": "39395075"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as  unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-311V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-311V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-311V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60952",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Transportation Execution",
                    "text": "39395218"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution.  Successful attacks of this vulnerability can result in takeover of Oracle Transportation Execution. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1060V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1060V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1060V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60953",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Telecommunications Billing Integrator",
                    "text": "39395245"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Telecommunications Billing Integrator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Telecommunications Billing Integrator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Telecommunications Billing Integrator accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1300V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1300V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1300V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60957",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Transportation Execution",
                    "text": "39395329"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Transportation Execution accessible data as well as  unauthorized read access to a subset of Oracle Transportation Execution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1060V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1060V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1060V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60959",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SDP Number Portability",
                    "text": "39395450"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle SDP Number Portability accessible data as well as  unauthorized access to critical data or complete access to all Oracle SDP Number Portability accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-217V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-217V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-217V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60960",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle SDP Number Portability",
                    "text": "39395494"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes to compromise Oracle SDP Number Portability.  While the vulnerability is in Oracle SDP Number Portability, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle SDP Number Portability. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-217V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-217V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-217V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60962",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Flow Manufacturing",
                    "text": "39395563"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Flow Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Flow Manufacturing accessible data as well as  unauthorized read access to a subset of Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-300V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-300V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-300V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60963",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Treasury",
                    "text": "39395596"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Treasury product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Treasury.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Treasury accessible data as well as  unauthorized access to critical data or complete access to all Oracle Treasury accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-512V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-512V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-512V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60965",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (France)",
                    "text": "39395682"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (France) accessible data as well as  unauthorized access to critical data or complete access to all Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-998V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-998V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-998V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60966",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Human Resources",
                    "text": "39395689"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Human Resources accessible data as well as  unauthorized access to critical data or complete access to all Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-210V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-210V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-210V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60972",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Tax",
                    "text": "39395827"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Tax.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data as well as  unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1087V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1087V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1087V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60973",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Tax",
                    "text": "39395836"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle E-Business Tax executes to compromise Oracle E-Business Tax.  Successful attacks of this vulnerability can result in takeover of Oracle E-Business Tax. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1087V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1087V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1087V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60974",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Tax",
                    "text": "39395852"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Tax.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data as well as  unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1087V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1087V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1087V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60978",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Scripting",
                    "text": "39396104"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Scripting.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as  unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-433V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-433V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-433V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60979",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Scripting",
                    "text": "39396109"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting.  Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-433V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-433V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-433V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60982",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle US Federal Human Resources",
                    "text": "39396469"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle US Federal Human Resources.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle US Federal Human Resources accessible data as well as  unauthorized access to critical data or complete access to all Oracle US Federal Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-899V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-899V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-899V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60984",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Portfolio Analysis",
                    "text": "39396502"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as  unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1358V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1358V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1358V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60985",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Portfolio Analysis",
                    "text": "39396510"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1358V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1358V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1358V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60986",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Portfolio Analysis",
                    "text": "39396513"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as  unauthorized access to critical data or complete access to all Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1358V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1358V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1358V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60987",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Portfolio Analysis",
                    "text": "39396522"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as  unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1358V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1358V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1358V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60988",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Portfolio Analysis",
                    "text": "39396529"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis.  Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1358V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1358V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1358V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60989",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Collections",
                    "text": "39396580"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Collections.  Successful attacks of this vulnerability can result in takeover of Oracle Advanced Collections. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-782V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-782V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-782V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60997",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Universal Work Queue",
                    "text": "39396713"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Non-Media Integration issues).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as  unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-778V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-778V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-778V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60999",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Data Integrator",
                    "text": "39396918"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2196V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2196V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2196V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61000",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Systems",
                    "text": "39397059"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-743V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-743V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-743V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61004",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Landed Cost Management",
                    "text": "39397140"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Landed Cost Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4568V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4568V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4568V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61005",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Logistics",
                    "text": "39397159"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Logistics accessible data as well as  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Logistics accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-740V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-740V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-740V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61006",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Logistics",
                    "text": "39397167"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics.  Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Logistics. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-740V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-740V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-740V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61009",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Logistics",
                    "text": "39397199"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics.  While the vulnerability is in Oracle Process Manufacturing Logistics, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Logistics. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-740V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-740V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-740V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61010",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Systems",
                    "text": "39397254"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems.  Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-743V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-743V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-743V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61012",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Time and Labor",
                    "text": "39397261"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-311V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-311V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-311V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61013",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Time and Labor",
                    "text": "39397307"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor.  While the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data as well as  unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-311V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-311V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-311V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61014",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Inventory Management",
                    "text": "39397334"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management.  While the vulnerability is in Oracle Inventory Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-508V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-508V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-508V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61015",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Time and Labor",
                    "text": "39397371"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-311V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-311V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-311V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61019",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Customers Online",
                    "text": "39397426"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Customers Online accessible data as well as  unauthorized access to critical data or complete access to all Oracle Customers Online accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1284V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1284V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1284V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61020",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Customers Online",
                    "text": "39397478"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Customers Online accessible data as well as  unauthorized access to critical data or complete access to all Oracle Customers Online accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1284V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1284V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1284V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61023",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Inventory Management",
                    "text": "39397556"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Inventory Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-508V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-508V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-508V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61024",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iRecruitment",
                    "text": "39397597"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as  unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1193V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1193V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1193V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61025",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iRecruitment",
                    "text": "39397638"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iRecruitment.  Successful attacks of this vulnerability can result in takeover of Oracle iRecruitment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1193V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1193V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1193V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61026",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iRecruitment",
                    "text": "39397666"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iRecruitment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1193V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1193V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1193V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61027",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Cost Management",
                    "text": "39397717"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Inventory Costing).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management.  Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-569V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-569V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-569V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61028",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Inventory Management",
                    "text": "39397783"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Management. CVSS 3.1 Base Score 1.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-508V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-508V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 1.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-508V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61030",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Product Development",
                    "text": "39398083"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Product Development accessible data as well as  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Product Development accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-744V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-744V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-744V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61031",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financials Common Country",
                    "text": "39398120"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financials Common Country product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Country.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Country accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financials Common Country accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-375V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-375V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-375V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61035",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financials for the Americas",
                    "text": "39398368"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financials for the Americas product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financials for the Americas.  Successful attacks of this vulnerability can result in takeover of Oracle Financials for the Americas. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-918V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-918V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-918V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61036",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (Norway)",
                    "text": "39398389"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle HRMS (Norway) accessible data as well as  unauthorized read access to a subset of Oracle HRMS (Norway) accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1645V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1645V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.8,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1645V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61037",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Loans",
                    "text": "39398401"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data as well as  unauthorized access to critical data or complete access to all Oracle Loans accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1537V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1537V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1537V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61039",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Supply Chain Planning",
                    "text": "39398539"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Advanced Supply Chain Planning. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-719V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-719V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-719V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61041",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Demantra Demand Management",
                    "text": "39398754"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demantra Demand Management.  While the vulnerability is in Oracle Demantra Demand Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2100V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2100V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2100V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61043",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Production Scheduling",
                    "text": "39398809"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Production Scheduling, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data as well as  unauthorized read access to a subset of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1983V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1983V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1983V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61044",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Production Scheduling",
                    "text": "39398815"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Production Scheduling.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data as well as  unauthorized read access to a subset of Oracle Production Scheduling accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Production Scheduling. CVSS 3.1 Base Score 4.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1983V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1983V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1983V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61046",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Production Scheduling",
                    "text": "39398826"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Production Scheduling.  While the vulnerability is in Oracle Production Scheduling, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data as well as  unauthorized read access to a subset of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1983V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1983V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1983V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61047",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Production Scheduling",
                    "text": "39398891"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1983V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1983V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 1.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1983V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61048",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Inventory Optimization",
                    "text": "39398916"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Optimization.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Optimization. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1067V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1067V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1067V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61049",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Production Scheduling",
                    "text": "39398936"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Production Scheduling executes to compromise Oracle Production Scheduling.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Production Scheduling. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1983V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1983V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1983V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61050",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Production Scheduling",
                    "text": "39399160"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1983V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1983V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1983V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61051",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Concurrent Processing",
                    "text": "39399775"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Concurrent Processing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Concurrent Processing accessible data as well as  unauthorized read access to a subset of Oracle Concurrent Processing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Concurrent Processing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9303V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9303V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9303V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61052",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Solaris",
                    "text": "39414218"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems).   The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10006V-11.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10006V-11.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU273"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10006V-11.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61053",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
                    "text": "39416817"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9742V-15.2.0.0.0",
                    "P-9742V-15.0.1.0.0",
                    "P-9742V-15.0.0.0.0",
                    "P-9742V-15.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU227"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9742V-15.0.0.0.0",
                        "P-9742V-15.2.0.0.0",
                        "P-9742V-15.0.1.0.0",
                        "P-9742V-15.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61055",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Order Management",
                    "text": "39420673"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Order Management executes to compromise PeopleSoft Enterprise SCM Order Management.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise SCM Order Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5127V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5127V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5127V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61056",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Grants",
                    "text": "39420881"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Grants.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Grants accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN Grants accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4995V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4995V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4995V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61057",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN eSettlements",
                    "text": "39420989"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN eSettlements.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN eSettlements accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4987V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4987V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4987V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61059",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Order Management",
                    "text": "39425589"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Order Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Order Management accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5127V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5127V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5127V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61060",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Suite Secure Enterprise Search",
                    "text": "39427257"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Secure Enterprise Search.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Suite Secure Enterprise Search accessible data as well as  unauthorized read access to a subset of Oracle E-Business Suite Secure Enterprise Search accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4574V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4574V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4574V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61061",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39428445"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61062",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Cash Management",
                    "text": "39432712"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Cash Management executes to compromise PeopleSoft Enterprise FIN Cash Management.  While the vulnerability is in PeopleSoft Enterprise FIN Cash Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Cash Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4979V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4979V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4979V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61063",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Supplier Contract Management",
                    "text": "39432750"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Supplier Contract Management product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Supplier Contract Management executes to compromise PeopleSoft Enterprise SCM Supplier Contract Management.  While the vulnerability is in PeopleSoft Enterprise SCM Supplier Contract Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise SCM Supplier Contract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5137V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5137V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5137V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61064",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iRecruitment",
                    "text": "39433884"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle iRecruitment accessible data as well as  unauthorized read access to a subset of Oracle iRecruitment accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1193V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1193V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1193V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61065",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39433991"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61067",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39434858"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61068",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Billing Argentina",
                    "text": "39435728"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of Oracle PeopleSoft (component: Billing).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Billing Argentina.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Billing Argentina. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4975V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4975V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4975V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61069",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN General Ledger Argentina",
                    "text": "39435765"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General Ledger).   The supported version that is affected is 9.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN General Ledger Argentina.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN General Ledger Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN General Ledger Argentina. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4993V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4993V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4993V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61070",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Common Objects Argentina",
                    "text": "39435813"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Cash Management).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8930V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8930V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8930V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61071",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Engineering Argentina",
                    "text": "39435834"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering).   The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Engineering Argentina.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Engineering Argentina accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN Engineering Argentina accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4913V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4913V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.3,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4913V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61072",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Staffing Front Office Brazil",
                    "text": "39435862"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office Brazil.  While the vulnerability is in PeopleSoft Enterprise FIN Staffing Front Office Brazil, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8880V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8880V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8880V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61073",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Common Objects Brazil",
                    "text": "39435888"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Purchasing).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Brazil accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8936V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8936V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8936V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61074",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Common Objects Brazil",
                    "text": "39435896"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement).   The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8936V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8936V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8936V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61075",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Self-Service Human Resources",
                    "text": "39436790"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Self-Service Human Resources accessible data as well as  unauthorized read access to a subset of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1566V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1566V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1566V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61076",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Talent Acquisition Manager",
                    "text": "39438949"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager.  While the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Talent Acquisition Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5078V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5078V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5078V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61077",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Mobile Inventory Management",
                    "text": "39439266"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Mobile Inventory Management executes to compromise PeopleSoft Enterprise SCM Mobile Inventory Management.  While the vulnerability is in PeopleSoft Enterprise SCM Mobile Inventory Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Mobile Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8890V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8890V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8890V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61078",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CC Common Application Objects",
                    "text": "39441562"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise CC Common Application Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CC Common Application Objects accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8911V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8911V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8911V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61079",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39442259"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Libraries).  Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and  23.4-23.26.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle GoldenGate accessible data as well as  unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 5.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.2",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61080",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Public Sector Human Resources",
                    "text": "39447848"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Public Sector Human Resources accessible data as well as  unauthorized read access to a subset of Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-210V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-210V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-210V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Joakim B�low"
                    ]
                }
            ],
            "cve": "CVE-2026-61081",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39449066"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.4.0-8.4.10",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-8.0.0-8.0.47",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Performance Schema)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Performance Schema)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Fushuling"
                    ]
                },
                {
                    "names": [
                        "RacerZ"
                    ]
                }
            ],
            "cve": "CVE-2026-61082",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Connectors",
                    "text": "39449361"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8576(MySQL Connectors_Connector/J)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61083",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Performance Management",
                    "text": "39452184"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Performance Management accessible data as well as  unauthorized read access to a subset of Oracle Performance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4425V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4425V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4425V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61084",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39464010"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Libraries).  Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and  23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data as well as  unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.2",
                    "P-5757V-19.1.0.0.0-19.30.0.0",
                    "P-5757V-21.3-21.21"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.2",
                        "P-5757V-19.1.0.0.0-19.30.0.0",
                        "P-5757V-21.3-21.21"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61085",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Inventory",
                    "text": "39465773"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Inventory.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Inventory accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5124V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5124V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5124V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61086",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Order Management",
                    "text": "39465775"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Order Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Order Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5127V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5127V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5127V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61087",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Payables",
                    "text": "39465803"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Payables.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Payables accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5008V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5008V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5008V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61088",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Manufacturing",
                    "text": "39465816"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Manufacturing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5126V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5126V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5126V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61089",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Inventory",
                    "text": "39465834"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Inventory.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Inventory accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM Inventory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5124V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5124V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5124V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61090",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Foundation",
                    "text": "39468252"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Miscellaneous).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Foundation executes to compromise Oracle Project Foundation.  Successful attacks of this vulnerability can result in takeover of Oracle Project Foundation. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1293V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1293V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1293V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61091",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39473155"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and  15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.0.0.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.2.0.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.0.1.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.1.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.2.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.1.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.0.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.2.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.0.1.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_BRM Server)V-15.1.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61092",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39473510"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Haogang Mao"
                    ],
                    "organization": "SKLCCSE Lab at Beihang University"
                },
                {
                    "names": [
                        "Jie Liang"
                    ],
                    "organization": "SKLCCSE Lab at Beihang University"
                }
            ],
            "cve": "CVE-2026-61093",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39474810"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Quan Huynh"
                    ],
                    "organization": "Calif.io"
                }
            ],
            "cve": "CVE-2026-61094",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39474825"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Replication)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Replication)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61095",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
                    "text": "39477856"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security).  Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and  8.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4516V-7.7.0",
                    "P-4516V-7.8.0",
                    "P-4516V-8.0.1",
                    "P-4516V-7.5.0",
                    "P-4516V-7.5.1",
                    "P-4516V-7.6.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU224"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4516V-7.7.0",
                        "P-4516V-7.8.0",
                        "P-4516V-8.0.1",
                        "P-4516V-7.5.0",
                        "P-4516V-7.5.1",
                        "P-4516V-7.6.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61096",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39478664"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.0.0-8.0.47"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Pluggable Auth)V-8.0.0-8.0.47"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61097",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Trade Finance Process Management",
                    "text": "39478987"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance Process Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance Process Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance Process Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Trade Finance Process Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Trade Finance Process Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13718V-14.6.0-14.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13718V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13718V-14.6.0-14.8.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61098",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39479071"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61099",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39479081"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61100",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39479103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61101",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle MES for Process Manufacturing",
                    "text": "39481232"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data as well as  unauthorized update, insert or delete access to some of Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1776V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1776V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1776V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61102",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Trade Finance",
                    "text": "39485183"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14134V-14.6.0-14.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14134V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14134V-14.6.0-14.8.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61103",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Campus Community",
                    "text": "39486857"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise CS Campus Community executes to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5183V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5183V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5183V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61104",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Student Records",
                    "text": "39487035"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5182V-9.2.38"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5182V-9.2.38"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5182V-9.2.38"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61105",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Trade Finance",
                    "text": "39487600"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure).  Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14134V-14.6.0-14.8.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14134V-14.6.0-14.8.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14134V-14.6.0-14.8.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61106",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GoldenGate",
                    "text": "39487942"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle GoldenGate (component: Config Service Executable).  Supported versions that are affected are 23.4-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5757V-23.4-23.26.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5757V-23.4-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5757V-23.4-23.26.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61107",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications DBA",
                    "text": "39488282"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA.  Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-166V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-166V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-166V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "vnth4nhnt"
                    ]
                }
            ],
            "cve": "CVE-2026-61108",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39489004"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: GIS)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: GIS)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: GIS)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: GIS)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: GIS)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: GIS)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "vnth4nhnt"
                    ]
                }
            ],
            "cve": "CVE-2026-61109",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39489024"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-8.0.0-8.0.47",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-8.4.0-8.4.10",
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-8.4.0-8.4.10"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-8.4.0-8.4.10",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-8.0.0-8.0.47",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: JSON)V-9.7.0-9.7.1",
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: JSON)V-8.4.0-8.4.10"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61110",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications DBA",
                    "text": "39493457"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA.  Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-166V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-166V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-166V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61111",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39493652"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library.  While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61112",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Management",
                    "text": "39493844"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-497V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-497V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-497V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61113",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39493883"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61114",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39494017"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61115",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Management",
                    "text": "39494134"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management.  Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-497V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-497V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-497V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61116",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39494141"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61117",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (UK)",
                    "text": "39495029"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK).  While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1001V-12.2.8-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1001V-12.2.8-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1001V-12.2.8-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61119",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (UK)",
                    "text": "39495349"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (UK). CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1001V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1001V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1001V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61120",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (US)",
                    "text": "39495407"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US).  Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1000V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1000V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1000V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61121",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (UK)",
                    "text": "39495425"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).  Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK).  Successful attacks of this vulnerability can result in takeover of Oracle HRMS (UK). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1001V-12.2.8-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1001V-12.2.8-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1001V-12.2.8-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61122",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (UK)",
                    "text": "39495441"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).  Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data as well as  unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1001V-12.2.9-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1001V-12.2.9-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1001V-12.2.9-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61123",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (US)",
                    "text": "39495457"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle HRMS (US) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (US). CVSS 3.1 Base Score 4.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1000V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1000V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1000V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61125",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Configure to Order",
                    "text": "39498309"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configure to Order.  While the vulnerability is in Oracle Configure to Order, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Configure to Order accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-776V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-776V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-776V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61126",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
                    "text": "39499380"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform).  Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0-15.2.0.0.0",
                    "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0-15.0.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0-15.2.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0-15.0.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU222"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.1.0.0.0-15.2.0.0.0",
                        "P-2136(Oracle Communications Billing and Revenue Management_Platform)V-15.0.0.0.0-15.0.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61127",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39499511"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer).  Supported versions that are affected are 8.0.0.7.0-8.3.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0.0.7.0-8.3.0.2.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0.0.7.0-8.3.0.2.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU221"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2283V-8.0.0.7.0-8.3.0.2.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61128",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39501528"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61129",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39503762"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61130",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39503834"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61131",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39503866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61132",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39504376"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data as well as  unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61133",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39504420"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61134",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39504702"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61135",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39504743"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61136",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39505144"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as  unauthorized read access to a subset of Oracle Commerce Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61137",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Platform",
                    "text": "39505158"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9348V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9348V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9348V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61138",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Complex Maintenance, Repair and Overhaul",
                    "text": "39507780"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul.  While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data as well as  unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1184V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1184V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1184V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61140",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39508103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61141",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Benefits",
                    "text": "39516041"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act).  Supported versions that are affected are 12.2.7-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits.  Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-290V-12.2.7-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-290V-12.2.7-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-290V-12.2.7-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61142",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payroll",
                    "text": "39520591"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll.  While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-506V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-506V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-506V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61143",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
                    "text": "39524507"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF).  Supported versions that are affected are 15.0.0.0.0 and  15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-12985V-15.0.0.0.0",
                    "P-12985V-15.2.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12985V-15.2.0.0.0",
                        "P-12985V-15.0.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU225"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-12985V-15.2.0.0.0",
                        "P-12985V-15.0.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61144",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of MySQL Server",
                    "text": "39525738"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                    "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU210"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8478(MySQL Cluster MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1",
                        "P-8478(MySQL Server MySQL Server, MySQL Cluster_Server: Optimizer)V-9.7.0-9.7.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61145",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527406"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61146",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527408"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61147",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527758"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61148",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527879"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61149",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527886"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61150",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527888"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61151",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527894"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61152",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527905"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61153",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527930"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61154",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "39528129"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search Platform Services. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61155",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "39528139"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search Platform Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61156",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "39528146"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search Platform Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61157",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528172"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61158",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528176"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61159",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528181"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61160",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528187"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61161",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528200"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61162",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528453"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61163",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528468"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61164",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528473"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Content Acquisition System)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61165",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
                    "text": "39529134"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search Platform Services and  unauthorized read access to a subset of Oracle Commerce Guided Search Platform Services accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU274"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search Platform Services_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61166",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529346"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61167",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529350"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61168",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529368"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61169",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529439"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM.  While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61170",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529585"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).   The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61171",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529623"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61172",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529628"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61173",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529681"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).   The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61174",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39529861"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics.  While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 9.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9387V-3.6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9387V-3.6.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61175",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39529868"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.3 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9387V-3.6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9387V-3.6.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61176",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39529960"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9387V-3.6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9387V-3.6.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61178",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530539"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61179",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530641"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61180",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530643"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61181",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530648"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile Product Lifecycle Management for Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data as well as  unauthorized update, insert or delete access to some of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61182",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530668"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Product Lifecycle Management for Process executes to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61183",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530748"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61184",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530754"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile Product Lifecycle Management for Process accessible data as well as  unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61185",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530817"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Product Lifecycle Management for Process executes to compromise Oracle Agile Product Lifecycle Management for Process.  While the vulnerability is in Oracle Agile Product Lifecycle Management for Process, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61186",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39530819"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as  unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.4,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61187",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39530848"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 2.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.8,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61188",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
                    "text": "39530869"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation).   The supported version that is affected is 6.2.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4445V-6.2.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4445V-6.2.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4445V-6.2.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61189",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39530876"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management.  While the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61190",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39530901"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).   The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61191",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39530905"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61192",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39530923"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).   The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61194",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39531125"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61195",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39531137"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU278"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61196",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39535307"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61197",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39535322"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61200",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Labor Distribution",
                    "text": "39553755"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data as well as  unauthorized read access to a subset of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-326V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-326V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-326V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61201",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CRM Common Objects",
                    "text": "39558666"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects).   The supported version that is affected is 9.2.23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CRM Common Objects.  While the vulnerability is in PeopleSoft Enterprise CRM Common Objects, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CRM Common Objects. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8904V-9.2.23"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8904V-9.2.23"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8904V-9.2.23"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61202",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Solaris",
                    "text": "39561009"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).  Supported versions that are affected are 11.3 and  11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as  unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10006V-11.4",
                    "P-10006V-11.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10006V-11.4",
                        "P-10006V-11.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU273"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10006V-11.4",
                        "P-10006V-11.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61203",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Expenses",
                    "text": "39565721"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Expenses accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Expenses accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Expenses. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4988V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4988V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.4,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4988V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61204",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Program Management",
                    "text": "39565963"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Program Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Program Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Program Management. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5012V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5012V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5012V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61205",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Purchasing",
                    "text": "39566173"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Purchasing accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5133V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5133V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5133V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61207",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM eProcurement",
                    "text": "39570819"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement.  While the vulnerability is in PeopleSoft Enterprise SCM eProcurement, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eProcurement accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5118V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5118V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5118V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61209",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft In-Memory Project Discovery",
                    "text": "39571988"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery.  While the vulnerability is in PeopleSoft In-Memory Project Discovery, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft In-Memory Project Discovery. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10681V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10681V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10681V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61210",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Manufacturing",
                    "text": "39572844"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise SCM Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Manufacturing accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Manufacturing accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5126V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5126V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU277"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5126V-9.2"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "HexRabbit"
                    ],
                    "organization": "DEVCORE Research Team"
                }
            ],
            "cve": "CVE-2026-61211",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39575331"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.31 and  23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS.  While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.2",
                    "P-5(RDBMS)V-19.3-19.31"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU199"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-19.3-19.31",
                        "P-5(RDBMS)V-23.4.0-23.26.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61214",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (UK)",
                    "text": "39587462"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1001V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1001V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1001V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61216",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Payroll",
                    "text": "39591543"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Payroll accessible data as well as  unauthorized read access to a subset of Oracle Payroll accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Payroll. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-506V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-506V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-506V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61217",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Security Service",
                    "text": "39591653"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Security Service accessible data as well as  unauthorized access to critical data or complete access to all Oracle Security Service accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-991V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-991V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU211"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-991V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61218",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle E-Business Suite Secure Enterprise Search",
                    "text": "39192147"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Secure Enterprise Search.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Suite Secure Enterprise Search accessible data as well as  unauthorized access to critical data or complete access to all Oracle E-Business Suite Secure Enterprise Search accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4574V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4574V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4574V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61220",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Origination",
                    "text": "39597849"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration).   The supported version that is affected is 14.5.0.16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as  unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14325V-14.5.0.16.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14325V-14.5.0.16.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14325V-14.5.0.16.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61221",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Item Master",
                    "text": "39618783"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Item Master product of Oracle E-Business Suite (component: iSet-up bugs).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Item Master.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Item Master accessible data as well as  unauthorized read access to a subset of Oracle Item Master accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1739V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1739V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"